HassounaKhalil

JomSocial ~ Joomla Shell Upload Vulnerability

Sep 9th, 2014
640
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.09 KB | None | 0 0
  1. ####################################################
  2. _____
  3. /\ / ____|
  4. / \ _ __ ___ _ __ | (___ ___ ___
  5. / /\ \ | '_ \ / _ \ | '_ \ \___ \ / _ \ / __|
  6. / ____ \ | | | || (_) || | | | ____) || __/| (__
  7. /_/ \_\|_| |_| \___/ |_| |_||_____/ \___| \___|
  8.  
  9.  
  10. ####################################################
  11. JomSocial ~ Joomla Shell Upload Vulnerability
  12. ~Dorks~
  13. inurl:/com_community/
  14. inurl:/images/originalvideos/
  15. inurl:/index.php?option=com_community&view=videos
  16. Hassouna Khalil from #AnonSec Team
  17. ####################################################
  18. ####################################################
  19. Stuff you need:
  20. Firefox
  21. A Shell
  22. Tamper Data
  23. Vulnerable Site
  24. & a Brain :)
  25. ####################################################
  26. Preparation:
  27. 1. Get a shell here. (recommend: c99.php)
  28. 2. Download Tamper Data
  29. 3. Find a vuln site. *refer to Dorking*
  30. ####################################################
  31. Dorks:
  32. inurl:/com_community/
  33. inurl:/images/originalvideos/
  34. inurl:/index.php?option=com_community&view=videos
  35. ####################################################
  36. Preparing your Shell:
  37. 1. Download a shell.
  38. 2. Put it in a folder (ex. "myshell")
  39. 3. Copy the shell to the same folder and rename it to "yourshell.php.flv"
  40. 4. Now in your folder you have 2 files, "myshell.php" & "myshell.php.flv".
  41. ####################################################
  42. Getting Access to site:
  43. 1. Register a fake account.
  44. 2. Active your fake account.
  45. 3. Go to your profile page.
  46. 4. Click on Add Video.
  47. 5. Choose upload video from computer.
  48. ####################################################
  49. Uploading your Shell:
  50. Upload a video from your computer, please note that if you only see Add video from URL that means the site is not vuln.
  51. The reason for having created a file called "myshell.php.flv", is to trick the uploader into thinking that you are uploading a FLV file.
  52. ####################################################
  53. Uploading shell:
  54. 1. Go to upload page, click on add video.
  55. 2. Select Add video.
  56. 3. Select Upload from Computer.
  57. 4. Browse to your "myshell.php.flv".
  58. 5. Input Title.
  59. **before you click on upload**
  60. 6. Firefox -> Tools -> Tamper Data, click on Start Tamper Data.
  61. 7. Now click UPLOAD.
  62. 8. Tamper data will then show you if you want to tamper, uncheck continue to tamper then click on tamper.
  63. 9. Look for "myshell.php.flv" then delete the .flv part meaning you will have "myshell.php" left.
  64. 10. SUBMIT.
  65. 11. Wait for it, and you will see the successful upload page.
  66. 12. Congrats you have uploaded a shell.
  67. ####################################################
  68. Shell location:
  69. 1. Go to http://[VICTIM]/images/originalvideos/
  70. 2. There you will find folders named in numbers. (yours is most likely the last/bottom folder)
  71. 3. Most of the folders will contain .flv, .avi && etc etc.
  72. 4. Your folder will contain a random generated name with a PHP file extension.
  73. 5. Open your "random.php"
  74. 6. And your IN!
Advertisement
Add Comment
Please, Sign In to add comment