|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
How to SQL Inject Joomla? |
|
Posted: Sat Sep 27, 2008 5:55 pm |
|
|
SnIpEr |
Active user |
|
|
Joined: Sep 25, 2008 |
Posts: 37 |
|
|
|
|
|
|
|
I tried to test if a Joomla site was vulnerable, but whenever I try to enter the login like this:
- Login: hi' or 1=1--
- Pass: hi' or 1=1--
I always get this screen:
I was thinking maybe you guys could suggest a a few other methods of testing for vulnerabilities, and then maybe walk me through this, if possible. Thanks :D |
|
|
|
|
Posted: Sat Sep 27, 2008 6:00 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
You must be joking, right?
Seriously, you can't hope to find such simple security holes from joomla. I can tell you, that i am going to release advisory about some sec probs in joomla, but these are minor probs, not sql injection ...
And please edit your screenshot in order to hide private information (URL)!! |
|
|
|
|
Posted: Sun Sep 28, 2008 3:55 am |
|
|
SnIpEr |
Active user |
|
|
Joined: Sep 25, 2008 |
Posts: 37 |
|
|
|
|
|
|
|
umm, no.. I wasn't joking. People all around unamimously agree that Joomla is the easiest to hack. |
|
|
|
|
Posted: Sun Sep 28, 2008 11:57 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
SnIpEr wrote: | umm, no.. I wasn't joking. People all around unamimously agree that Joomla is the easiest to hack. |
Gimme a break ... joomla is hard-to-break by itself, as for sept 2008. This is the fact, i can assure after manual source code review recently. There are huge pile of various third-party insecure add-on's, but this is not joomla itself! |
|
|
|
|
Posted: Mon Sep 29, 2008 4:57 am |
|
|
SnIpEr |
Active user |
|
|
Joined: Sep 25, 2008 |
Posts: 37 |
|
|
|
|
|
|
|
hmm, I still consistently hear it's the easiest, aside from the new IPB exploit (Thanks so much, btw). I know a guy on another hacking website who easily hacks Joomlas, but I can't get into contact with him ) : |
|
|
|
|
www.waraxe.us Forum Index -> Joomla
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|