Joomla
1) Default users
joomla
admin2) Scan Joomla for information and vulnerabilities
joomscan --url http://domain.local/joomlajoomscan --url http://domain.local/joomla -ec3) Brute force Joomla administrator page
Nmap
joomla
adminsudo nano /usr/share/nmap/scripts/http-joomla-brute.nselocal DEFAULT_JOOMLA_LOGIN_URI = "/joomla/administrator/index.php"Admin Panel RCE (Requires Credentials)
1) Edit error.php on Site Templates
Configuration files that might contain credentials
1) configuration.php
Last updated