Welcome to Journal of University of Chinese Academy of Sciences,Today is

›› 2015, Vol. 32 ›› Issue (6): 825-835.DOI: 10.7523/j.issn.2095-6134.2015.06.015

Previous Articles     Next Articles

Vulnerability exploitation for Joomla content management system

DONG Ying, ZHANG Yuqing, YUE Hongzhou   

  1. National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing 101408, China
  • Received:2014-08-01 Revised:2015-05-18 Online:2015-11-15

Abstract:

We propose and develop a vulnerability exploitation scheme, called JoomHack. We use online shared and updatable vulnerability detection library of attack patterns, traverse them to exploit vulnerabilities, use attack patterns in database as seeds to generate new ones, and bring higher success rates. Experiments show that JoomHack takes advantage over Joomscan and other penetration tools of superiority when exploiting Joomla-based web system. JoomHack exploits vulnerabilities, assess risk for Joomla site effectively, and lay the foundation for web security work such as bug fixes. It is effective and has low cost for the improvement of web security.

Key words: Joomla, shared vulnerability library, risk assessment, vulnerability exploit, web security

CLC Number: