 |
Menu |
 |
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
 |
User Info |
 |
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 110
Members: 0
Total: 110
|
|
|
|
|
 |
Full disclosure |
 |
CyberDanube Security Research 20251014-0 | Multiple Vulnerabilities in Phoenix Contact QUINT4 UPS
apis.google.com - Insecure redirect via __lu parameter(exploited in the wild)
Urgent Security Vulnerabilities Discovered in Mercku Routers Model M6a
Re: Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
Security Advisory: Multiple High-Severity Vulnerabilities in Suno.com (JWT Leakage, IDOR, DoS)
[SBA-ADV-20250730-01] CVE-2025-39664: Checkmk Path Traversal
[SBA-ADV-20250724-01] CVE-2025-32919: Checkmk Agent Privilege Escalation via Insecure Temporary Files
CVE-2025-59397 - Open Web Analytics SQL Injection
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Re: Defense in depth -- the Microsoft way (part 93): SRP/SAFERwhitelisting goes black on Windows 11
Re: [FD]: "Glass Cage" – Zero-Click iMessage ? Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain ? Secure Enclave Key Theft, Wormable RCE, Crypto Theft
Samtools v1.22.1 Uncontrolled Memory Allocation from Large BED Intervals Causes Denial-of-Service in Samtools/HTSlib
Samtools v1.22.1 Improper Handling of Excessive Histogram Bin Counts in Samtools Coverage Leads to Stack Overflow
|
|
|
|
|
|
 |
|
 |
 |
|
 |
IT Security and Insecurity Portal |
|
 |
How to SQL Inject Joomla? |
 |
Posted: Sat Sep 27, 2008 5:55 pm |
|
|
SnIpEr |
Active user |

 |
|
Joined: Sep 25, 2008 |
Posts: 37 |
|
|
|
 |
 |
 |
|
I tried to test if a Joomla site was vulnerable, but whenever I try to enter the login like this:
- Login: hi' or 1=1--
- Pass: hi' or 1=1--
I always get this screen:
I was thinking maybe you guys could suggest a a few other methods of testing for vulnerabilities, and then maybe walk me through this, if possible. Thanks :D |
|
|
|
|
Posted: Sat Sep 27, 2008 6:00 pm |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
You must be joking, right?
Seriously, you can't hope to find such simple security holes from joomla. I can tell you, that i am going to release advisory about some sec probs in joomla, but these are minor probs, not sql injection ...
And please edit your screenshot in order to hide private information (URL)!! |
|
|
|
|
Posted: Sun Sep 28, 2008 3:55 am |
|
|
SnIpEr |
Active user |

 |
|
Joined: Sep 25, 2008 |
Posts: 37 |
|
|
|
 |
 |
 |
|
umm, no.. I wasn't joking. People all around unamimously agree that Joomla is the easiest to hack. |
|
|
|
|
Posted: Sun Sep 28, 2008 11:57 am |
|
|
waraxe |
Site admin |

 |
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
 |
 |
 |
|
SnIpEr wrote: | umm, no.. I wasn't joking. People all around unamimously agree that Joomla is the easiest to hack. |
Gimme a break ... joomla is hard-to-break by itself, as for sept 2008. This is the fact, i can assure after manual source code review recently. There are huge pile of various third-party insecure add-on's, but this is not joomla itself! |
|
|
|
|
Posted: Mon Sep 29, 2008 4:57 am |
|
|
SnIpEr |
Active user |

 |
|
Joined: Sep 25, 2008 |
Posts: 37 |
|
|
|
 |
 |
 |
|
hmm, I still consistently hear it's the easiest, aside from the new IPB exploit (Thanks so much, btw). I know a guy on another hacking website who easily hacks Joomlas, but I can't get into contact with him ) : |
|
|
|
|
www.waraxe.us Forum Index -> Joomla
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|