This project provides a detailed lab simulation of a supply chain attack on the Drupal update system. It showcases the exploitation of sensitive endpoints through MITM and LFI, leading to Remote Code Execution. Comprehensive technical details and scripts are provided for educational purposes, emphasizing the importance of security awareness.
This repository serves as a comprehensive demonstration of a simulated supply chain attack targeting the update mechanism of Drupal, specifically tested on versions 9.5.10, 10.1.0, 11.0.8, and 11.1.3. The simulation showcases the following components:
release-history.xml to manipulate the update process.All processes, configurations, and associated scripts are outlined in meticulous detail within the PoC PDF. Some scripts may not be publicly available but can be shared upon request.
The outlined attack scenario operates through the following phases:
updates.drupal.org using a forged SSL certificate.Note: The execution of this exploit hinges upon both network or DNS control (MITM) and admin interaction. This serves as a simulation of a supply chain attack rather than a direct Drupal core vulnerability.
This project provides insights into:
This simulation does not exploit any vulnerabilities within the Drupal core. Testing was conducted solely in a controlled lab setting using non-production data. Users are advised not to employ these methodologies against any system they do not own or without explicit permission. This research is intended for educational, awareness, and defensive purposes only.
No comments yet.
Sign in to be the first to comment.