Joomla Mass LFI Scanner (70+ Exploit)


Joomla Mass LFI Scanner (Auto Download Configuration.php And Try Connect DB) (70+ Exploit)

Joomla Mass LFI Scanner is a multi-threaded, automated tool for hunting Local File Inclusion (LFI) vulnerabilities on Joomla-powered sites.
It uses 70+ public LFI vectors (paths hidden in this public version), attempts to auto-download the legendary configuration.php, extracts credentials, and even tries to connect to the remote MySQL DB if found.
Fast, loud, and pure hacker energy.

🔥 Features

  • Ultra-fast mass scan (threaded, suitable for 1000+ sites)
  • 70+ LFI vectors (pool hidden for sharing — use your own for max pwnage)
  • Auto parses Joomla config.php and extracts DB, FTP, secret, etc.
  • Attempts remote MySQL connect with found creds
  • Logs both all results and only vulnerable sites separately
  • Clean console & file output — easy for parsing or automation
  • Hacker-themed banners & warnings everywhere

🧰 Requirements

  • Python 3.8+ (tested on Python 3.8/3.9/3.10/3.11)
  • Install dependencies with: pip install requests pymysql urllib3

Optional (for max speed): Linux or Unix environment, fast connection, large site lists.
💀 Always hack responsibly!

🛠️ Usage

python3 joomscan.py lfi sites.txt
python3 joomscan.py lfi http://target-joomla-site.com

  • sites.txt = list of target sites (one per line)
  • Or scan a single site directly

📝 Output Example

http://site.com | Joomla LFI Multi-Path | lfi | VULNERABLE | http://site.com/index.php?... | db_user:root|db_pass:hackme|db_host:127.0.0.1|db_name:joomla_db|REMOTEDB:YES

  • All results → results_joomla.txt
  • Only vulnerable sites → success_joomla.txt

Other Shells

BypassServ Mini Shell
The BypassServ Mini Shell is a highly advanced backdoor webshell designed to…
Back Hack Bypass Shell
Back|Hack Shell IV is an advanced, feature-rich PHP webshell and exploitation panel…
WordPress CloakPanel – Mini Hidden Javascript/PHP WordPress Admin Panel
WordPress CloakPanel – Mini Hidden Javascript/PHP WordPress Admin Panel 📁 File Manager…
PHP Mini SQL Admin – Mini Adminer
✅ MySQL-only support (via PDO) ✅ Inline editing with textarea for JSON/long…
D7net Web Shell Bypass
D7net Web Shell Bypass Download
Privdayz Special WordPress Backdoor Shell
Privdayz Special WordPress Backdoor Shell is a highly specialized tool designed for…
Ribel Cyber Team Simple File Manager
The Simple File Manager is a lightweight PHP-based application developed by RibelCyberTeam.…
mini privdayz shell 2023 Imunify360/403/406 bypass
Bypass 403 Forbidden, 406 Not Acceptable, Imunify360 with mini privdayz shell.
Python Google Dorker Tool
How to use:   python3 google_dorker.py dorklist.txt