Security Device

Peace Of Mind

Hacking Joomla+Apache+Linux with ‘Knull Shell’

| January 16, 2012

Demonstrating how to test server security with the ‘Knull Shell’ PHP shell which contains a number of various reverse/bind/backpipe shells (PHP, Python, Perl, Telnet, Netcat). The Joomla reset password vulnerability is also demonstrated. Download ‘Knull Shell’ from https://code.google.com/p/knull-shell Duration : 0:15:29 Technorati Tags: apache, backpipe, joomla, knull, Linux, ncat, netcat, perl, PHP, python, shell, telnet

Joomla Plugin Exploit + PHP Malware

| November 29, 2011

Blog: http://security-obscurity.blogspot.com Garden Store has a vulnerable version (1.1.7) of virtuemart (Joomla plugin) and through a blind sql injection we can retrieve administrator credentials. We edit the main template and place into the footer tag a simple piece of code properly obfuscated to get user’s credit cards data. – virtuemart exploit found by TecR0c & [...]