Targeting websites and uploading shell via scanning Joomla scripts on server 05-22-2020, 05:27 PM
#1
Hello guys
Today I'll show you how to targeting websites by scanning website's script and uploading shell
Tested on Joomla
# Joomla
Joomla is a free and open-source content management system for publishing web content, developed by Open Source Matters, Inc. It is built on a model–view–controller web application framework that can be used independently of the CMS
# Enumeration
There's a many ways to enumerating joomla's components for any website
1st- Go to Bing.com and type "ip:0.0.0.0 ?option="
This will show up some components for websites
2nd- Open the website's index source page and search for "components" and you'll find some too
# Tools
- JoomScan
https://tools.kali.org/web-applications/joomscan
- Joomla Scanner
https://github.com/drego85/JoomlaScan
- wPJosDetect 3
https://pastebin.com/cVxX98d1
- HackerTarget
https://hackertarget.com/joomla-security-scan/
# Scanning
- After we know the components that installed on the website we can download it and scan it by using RIPS
https://www.ripstech.com/
- Also you can search at google for any exploit for the component by typing
"com_media exploit"
- Or you can use "JoomScan" it also searching for any exploit for any components found on the website
# Video
Now it's the time to watch this video
Sorry for my bad English
Hope you like this tutorial
Regards ~
ElSyad/.
Today I'll show you how to targeting websites by scanning website's script and uploading shell
Tested on Joomla
# Joomla
Joomla is a free and open-source content management system for publishing web content, developed by Open Source Matters, Inc. It is built on a model–view–controller web application framework that can be used independently of the CMS
# Enumeration
There's a many ways to enumerating joomla's components for any website
1st- Go to Bing.com and type "ip:0.0.0.0 ?option="
This will show up some components for websites
2nd- Open the website's index source page and search for "components" and you'll find some too
# Tools
- JoomScan
https://tools.kali.org/web-applications/joomscan
- Joomla Scanner
https://github.com/drego85/JoomlaScan
- wPJosDetect 3
https://pastebin.com/cVxX98d1
- HackerTarget
https://hackertarget.com/joomla-security-scan/
# Scanning
- After we know the components that installed on the website we can download it and scan it by using RIPS
https://www.ripstech.com/
- Also you can search at google for any exploit for the component by typing
"com_media exploit"
- Or you can use "JoomScan" it also searching for any exploit for any components found on the website
# Video
Now it's the time to watch this video
Sorry for my bad English
Hope you like this tutorial
Regards ~
ElSyad/.
The Best Revenge Ever Is Success !


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)