Wednesday, July 31, 2013

Introduction


 

Joomscan is a Joomla vulnerability scanner. It detects file inclusion, sql injection, command execution vulnerabilities of a target Joomla web site.


In this tutorial I’ll show you the usage and how to find vulnerabilities by joomscan.


Procedure

 

How to open it:-

 



  • Goto Backtrack >> Vulnerability Assessment >> Web Application Assessment >> CMS Vulnerability Identification >> joomscan, or you can open it through terminal also cd /pentest/web/joomscan.


Untitled


 


How to use it:-




  • To scan a targeted web site, use this command perl ./joomscan.pl -u <url>


Untitled (1)


 



  • To scan a targeted web site using proxy, use this command

  • perl ./joomscan.pl -u <url> -x ip:port


Untitled (2)


 


Thats it. There are few more options available for this tool. Just use this command to see all available options perl ./joomscan.pl .


 

31 Jul 2013

0 comments :

Post a Comment

:) :)) ;(( :-) =)) ;( ;-( :d :-d @-) :p :o :>) (o) [-( :-? (p) :-s (m) 8-) :-t :-b b-( :-# =p~ $-) (b) (f) x-) (k) (h) (c) cheer
Click to see the code!
To insert emoticon you must added at least one space before the code.