Sinisterly
Tutorial Targeting websites and uploading shell via scanning Joomla scripts on server - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: Tutorial Targeting websites and uploading shell via scanning Joomla scripts on server (/Thread-Tutorial-Targeting-websites-and-uploading-shell-via-scanning-Joomla-scripts-on-server)



Targeting websites and uploading shell via scanning Joomla scripts on server - ElSyad - 05-22-2020

Hello guys
Today I'll show you how to targeting websites by scanning website's script and uploading shell
Tested on Joomla

# Joomla
Joomla is a free and open-source content management system for publishing web content, developed by Open Source Matters, Inc. It is built on a model–view–controller web application framework that can be used independently of the CMS

# Enumeration
There's a many ways to enumerating joomla's components for any website
1st- Go to Bing.com and type "ip:0.0.0.0 ?option="
This will show up some components for websites

2nd- Open the website's index source page and search for "components" and you'll find some too

# Tools
- JoomScan
https://tools.kali.org/web-applications/joomscan

- Joomla Scanner
https://github.com/drego85/JoomlaScan

- wPJosDetect 3
https://pastebin.com/cVxX98d1

- HackerTarget
https://hackertarget.com/joomla-security-scan/

# Scanning
- After we know the components that installed on the website we can download it and scan it by using RIPS
https://www.ripstech.com/

- Also you can search at google for any exploit for the component by typing
"com_media exploit"

- Or you can use "JoomScan" it also searching for any exploit for any components found on the website

# Video
Now it's the time to watch this video


Sorry for my bad English
Hope you like this tutorial
Regards ~
ElSyad/.