Waraxe IT Security Portal
Login or Register
July 27, 2024
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 207
Members: 0
Total: 207
Full disclosure
CyberDanube Security Research 20240722-0 | Multiple Vulnerabilities in Perten/PerkinElmer ProcessPlus
[KIS-2024-06] XenForo <= 2.2.15 (Template System) Remote Code Execution Vulnerability
[KIS-2024-05] XenForo <= 2.2.15 (Widget::actionSave) Cross-Site Request Forgery Vulnerability
CVE-2024-33326
CVE-2024-33327
CVE-2024-33328
CVE-2024-33329
CyberDanube Security Research 20240703-0 | Authenticated Command Injection in Helmholz Industrial Router REX100
SEC Consult SA-20240627-0 :: Local Privilege Escalation via MSI installer in SoftMaker Office / FreeOffice
SEC Consult SA-20240626-0 :: Multiple Vulnerabilities in Siemens Power Automation Products
Novel DoS Vulnerability Affecting WebRTC Media Servers
APPLE-SA-06-25-2024-1 AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8
40 vulnerabilities in Toshiba Multi-Function Printers
17 vulnerabilities in Sharp Multi-Function Printers
SEC Consult SA-20240624-0 :: Multiple Vulnerabilities allowing complete bypass in Faronics WINSelect (Standard + Enterprise)
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Newbies corner -> Joomla15 deface
Post new topicReply to topic View previous topic :: View next topic
Joomla15 deface
PostPosted: Mon Jun 15, 2009 7:06 pm Reply with quote
shyspy
Advanced user
Advanced user
Joined: Jun 08, 2009
Posts: 60




Hello,

joomla is not very easy to deface Or hack.

Came accross this http://www.cedricmccormick.com/

Please share more info on how it must have been done.

Also if any1 know how to deface an joomla1.5 please direct me.
View user's profile Send private message
PostPosted: Wed Jun 17, 2009 7:08 pm Reply with quote
HashManiac
Regular user
Regular user
Joined: May 13, 2009
Posts: 17




dude .. Joomla is easiest hacking script I think.
View user's profile Send private message
-
PostPosted: Thu Jun 18, 2009 8:12 am Reply with quote
shyspy
Advanced user
Advanced user
Joined: Jun 08, 2009
Posts: 60




HashManiac wrote:
dude .. Joomla is easiest hacking script I think.


Hi,

Can you share some more info and if possible show me how to.
I have been searching for it since long but found some joomla1 stuff nothing really working for j1.5
View user's profile Send private message
PostPosted: Thu Jun 18, 2009 1:03 pm Reply with quote
gibbocool
Advanced user
Advanced user
Joined: Jan 22, 2008
Posts: 208




There is an exploit for 1.5 that lets you reset the administrator's password.. It's kinda tricky tho and requires some practice, so practice by installing joomla on your own server first..

1. Go to url : target.com/index.php?option=com_user&view=reset&layout=confirm

2. Write into field "token" char: ' and Click OK.

3. Write new password for admin

4. Go to url : target.com/administrator/

5. Login admin with new password

_________________
http://www.gibbocool.com
View user's profile Send private message Visit poster's website
-
PostPosted: Thu Jun 18, 2009 1:31 pm Reply with quote
shyspy
Advanced user
Advanced user
Joined: Jun 08, 2009
Posts: 60




gibbocool wrote:
There is an exploit for 1.5 that lets you reset the administrator's password.. It's kinda tricky tho and requires some practice, so practice by installing joomla on your own server first..

1. Go to url : target.com/index.php?option=com_user&view=reset&layout=confirm

2. Write into field "token" char: ' and Click OK.

3. Write new password for admin

4. Go to url : target.com/administrator/

5. Login admin with new password


Hey nice info but doesn't work.
I tried it on my systemsolution.biz - just check it out its not working.
View user's profile Send private message
PostPosted: Thu Jun 18, 2009 1:59 pm Reply with quote
waraxe
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




As I can understand, you have installed newest version of Joomla, with no third-party add-ons? So what do you expect, 0-day exploits for Joomla? 0-days are valuable resource, they are kept in secret Smile
View user's profile Send private message Send e-mail Visit poster's website
PostPosted: Fri Jun 19, 2009 12:50 am Reply with quote
gibbocool
Advanced user
Advanced user
Joined: Jan 22, 2008
Posts: 208




Yes it doesnt work because you must have a patched version of joomla, or maybe something like magicquotes is preventing the exploit.

_________________
http://www.gibbocool.com
View user's profile Send private message Visit poster's website
-
PostPosted: Fri Jun 19, 2009 5:43 am Reply with quote
shyspy
Advanced user
Advanced user
Joined: Jun 08, 2009
Posts: 60




K ! i will try it on a few old versions..
thanks for the information.
View user's profile Send private message
its even not workin for me
PostPosted: Sat Jun 20, 2009 3:58 am Reply with quote
Cykotic_Cner
Beginner
Beginner
Joined: Jun 20, 2009
Posts: 3




i even tried d exploit ...but its not working..........i think Joomla must hav patched d loop hole............ Question
View user's profile Send private message
Joomla15 deface
www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.204 Seconds