「Neuromancer」Hacking sites with Joomla (Universidade USP)

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
19,449
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jan 16, 2010

Websites running Joomla v.1.5 are vulnerable to remote admin password change, we can do this simply using a direct string that will take us to the "token confirmation page" (The true admin WOULD receive the token in his e-mail, but we're not the TRUE admin :). After do that, we just put the " ' " char in the token field to bypass the authentication and change REMOTELY the admin's passwd.
The problem is found in file : ../components/com_user/models/reset.php (lines 111 - 130)
The victim was "USP - Universidade de São Paulo - RPM Section"

Subscribe and watch more attack techniques from neuromancer: www.youtube.com/neurom4nc3r

Secunia Advisory: SA31457
CVE-2008-3681

Link to this comment:

Share to:

Uploader Comments (neurom4nc3r)

  • Nice music... what's it called?

  • @ubudog32 Excuse the delay dude, the song is called "Synth Solo" (hidden track) from Children of Bodom

  • It doesn't work. You actually have to enter the token sent to the email address of the administrator, so you'd have to hack the admin's account first.

  • @rafvrab you're wrong. See the vid again

  • hehe, this does not work any more. Joomla have edited it in the files!! :D

  • @martinkolle95 yeah, its very very rare in nowadays as all old vulnerabilities. Today we have new ones, and thats is good (or not). lol.

see all

All Comments (17)

Sign In or Sign Up now to post a comment!
  • Hmm it ask me to verify from E-mail from admin hmm

  • It doesnt matter, you were Pwoned and Punked! The Police will laugh at you if you saay 'waynnnnhh... My joomla site was pwoned"

  • It doesnt matter, you were Pwoned and Punked!

  • @barkerAU linux -.-

  • I know this mac ;p'

  • @neurom4nc3r haha, maybe, for somone is it good!! :D

Loading...
Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more