Jump to content
TioSam

[Symlink] + Bypass AdminPanel Joomla + Exploit 0day Java7

Recommended Posts

Posted

joomla.png

Some attackers may determine that a website running on Joomla! site-web.com/administrator

But in some cases, when you type /administrator/ index.php automatically redirects us, then practically the attacker gives up because it thinks that the website is Joomla admin panel but has another name or another direction.

That happens for settings that the administrator has made ??to your Joomla, Plugin installed AdminExile [/ b] that allows administrators to add an access key to the end of the URL that redirects to erroneous entries page beginning on page 404, or anywhere else without seeing the login panel administrator.

Example:

- www.site-web.com/administrator/       <----- Redirecciona al index.php

- www.site-web.com/administrator/?key <----- Admin Panel

Once you have clicked on the second link, AdminExile password will be active until the session expires (or until the browser is closed).

For this case, I made a video demonstrating where achievement easily get the key (key) to enter the administrative site without problems.

Video:

Description: Getting the db settings (web) by Symlink, obtaining administrative username and password, "bypass" adminpane and placing the 0day Java7

Plugin AdminExile: AdminExile - Joomla! Extensions Directory

Grettings :)

  • Upvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...