Drupal
Discovery/Footprinting
#Verify Drupal on web server
Intrusionz3r0@htb[/htb]$ curl -s http://drupal.inlanefreight.local | grep Drupal
#Node: Drupal indexes its content using nodes. A node can hold anything such as a blog post, poll, article, etc. The page URIs are usually of the form /node/<nodeid>.
Intrusionz3r0@htb[/htb]$ curl -s http://drupal.inlanefreight.local/node/1
#uncover the version
Intrusionz3r0@htb[/htb]$ curl -s http://drupal-acc.inlanefreight.local/CHANGELOG.txt | grep -m2 ""
Attacking Drupal
PHP Filter Module
PHP Filter Module from version 8 onwards
Uploading a Backdoored Module
Leveraging Known Vulnerabilities
Drupalgeddon
Drupalgeddon2
Drupalgeddon3
Last updated