• Stars
    star
    161
  • Rank 232,119 (Top 5 %)
  • Language
    Python
  • License
    MIT License
  • Created over 3 years ago
  • Updated 5 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

๐Ÿฆ Juumla is a python tool created to identify Joomla version, scan for vulnerabilities and sensitive files

๐Ÿฆ Juumla




๐Ÿฆ Juumla is a python tool created to identify Joomla version, scan for vulnerabilities and search for config or backup files.


โšก Installing / Getting started

A quick guide on how to install and use Juumla.

1. Clone the repository - git clone https://github.com/oppsec/juumla.git
2. Install the libraries - pip3 install -r requirements.txt
3. Run Juumla - python3 main.py -u https://example.com

๐Ÿณ Docker

If you want to run Juumla in a Docker container, follow these commands:

1. Clone the repository - git clone https://github.com/oppsec/juumla.git
2. Build the image - sudo docker build -t juumla:latest .
3. Run container - sudo docker run juumla:latest



โš™๏ธ Pre-requisites

  • Python 3 installed on your machine.
  • Install the libraries with pip3 install -r requirements.txt



โœจ Features

  • Fast scan
  • Low RAM and CPU usage
  • Detect Joomla version
  • Find config and backup files
  • Scan for vulnerabilities based on the Joomla version
  • Open-Source



๐Ÿ“š To-Do

  • Update vulnerabilities database
  • Improve Joomla detection methods
  • Improve code optimization



๐Ÿ”จ Contributing

A quick guide on how to contribute to the project.

1. Create a fork from Juumla repository
2. Download the project with git clone https://github.com/your/juumla.git
3. Make your changes
4. Commit and makes a git push
5. Open a pull request



โš ๏ธ Warning

  • The developer is not responsible for any malicious use of this tool.

More Repositories

1

Pinkerton

๐Ÿ•ต๏ธ Pinkerton is an JavaScript file crawler and secret finder tool developed in Python
Python
282
star
2

tomcter

๐Ÿ˜น Tomcter is a python tool developed to bruteforce Apache Tomcat manager login with default credentials.
Python
97
star
3

Apepe

๐Ÿ“ฒ Enumerate information from an app based on the APK file
Python
76
star
4

WSOB

๐Ÿ˜ญ WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.
Python
28
star
5

Ozzy

[abandoned] ๐Ÿ‘ Ozzy is a dark omnipotent theme for IDA, Git Bash, Sublime, Visual Studio Code etc...
CSS
26
star
6

Squid

[abandoned] ๐Ÿฆ‘ Squid is NodeJS CLI tool to scan websites trying to find vulnerabilities.
JavaScript
24
star
7

Discor

[abandoned] โšก Discor is a Node.js tool created to help people which wants to create Discord bots more fast.
JavaScript
22
star
8

pwnfaces

๐Ÿ˜› Primefaces 5.X EL Injection Exploit (CVE-2017-1000486)
Go
20
star
9

extensions-wordlist

๐Ÿ” Improve your files enumeration with specific extensions!
17
star
10

breads

Breaking Active Directory Security with ๐Ÿž
Python
16
star
11

dbf

[abandoned] ๐Ÿ”ฅ DBF or Don't be Fired is a Visual Studio Code extension which send message boxes to remind you to avoid common mistakes
JavaScript
15
star
12

lovefetch

โค A CLI System Information Tool
Python
12
star
13

GWI

๐ŸŒ GWI is a python tool which uses Whois API to get website public information to help with your recon!
Python
8
star
14

OAO

โš™๏ธ Operating Account Operators (OAO) is a Golang tool to interact with the LDAP protocol to manage account groups, roles, ACLs/ACEs, etc...
Go
8
star
15

ILL

๐Ÿง I Love Linux (ILL) is a C tool developed to fast search for kernel vulnerabilities and suggest to the user
C
6
star
16

magenta

๐ŸŠ Python Magento Vulnerability Scanner
Python
6
star
17

Scythe

๐Ÿ’€ Collect JS and CSS files from websites.
JavaScript
6
star
18

zaber

๐Ÿ•ต๏ธ Yet another CVE-2019-9670 exploit, but in Golang.
Go
5
star
19

arbimz

๐Ÿ”ฅ Arbimz is a python tool created to exploit the vulnerability on Zimbra assigned as CVE-2019-9670.
Python
5
star
20

Gitter

๐Ÿ Python CLI tool to get public informations from a GitHub account
Python
4
star
21

MSI

๐Ÿ’ป CLI which gives informations about your system
Python
4
star
22

apekar

๐Ÿ‘พ Apekar is a Ruby CLI tool to analyze APK files to search for API keys, Secrets, Hosts and detect required permissions by the app.
Ruby
4
star
23

minebot

๐Ÿค– Charles is a minecraft bot made with mineflayer to execute simple commands
JavaScript
4
star
24

xcreen

๐Ÿ“ท Screenshot a list of websites quickly
Python
3
star
25

gitter-rust

Learning Rust - Project (1)
Rust
1
star
26

calc-go

๐Ÿ“ฑ Calculate fast with Go
Go
1
star
27

hasher

๐Ÿ”‘ Base85+Sha384 Hasher
Python
1
star
28

zobbix

๐Ÿ Zabbix 4.2 Auth Bypass
Python
1
star
29

oppsec.github.io-backup

A personal website :)
HTML
1
star
30

Hash4Me

๐Ÿ”‘Easily hash your text with MD5, SHA1, SHA256 and SHA512.
PHP
1
star
31

gitter-rb

๐Ÿ’Ž Yes a Gitter copy but it's Ruby now!
Ruby
1
star
32

aglpi

๐Ÿ–ฅ๏ธ against Gestionnaire Libre de Parc Informatique (GLPI)
Python
1
star