Joomla Mass LFI Scanner (70+ Exploit)


Joomla Mass LFI Scanner (Auto Download Configuration.php And Try Connect DB) (70+ Exploit)

Joomla Mass LFI Scanner is a multi-threaded, automated tool for hunting Local File Inclusion (LFI) vulnerabilities on Joomla-powered sites.
It uses 70+ public LFI vectors (paths hidden in this public version), attempts to auto-download the legendary configuration.php, extracts credentials, and even tries to connect to the remote MySQL DB if found.
Fast, loud, and pure hacker energy.

🔥 Features

  • Ultra-fast mass scan (threaded, suitable for 1000+ sites)
  • 70+ LFI vectors (pool hidden for sharing — use your own for max pwnage)
  • Auto parses Joomla config.php and extracts DB, FTP, secret, etc.
  • Attempts remote MySQL connect with found creds
  • Logs both all results and only vulnerable sites separately
  • Clean console & file output — easy for parsing or automation
  • Hacker-themed banners & warnings everywhere

🧰 Requirements

  • Python 3.8+ (tested on Python 3.8/3.9/3.10/3.11)
  • Install dependencies with: pip install requests pymysql urllib3

Optional (for max speed): Linux or Unix environment, fast connection, large site lists.
💀 Always hack responsibly!

🛠️ Usage

python3 joomscan.py lfi sites.txt
python3 joomscan.py lfi http://target-joomla-site.com

  • sites.txt = list of target sites (one per line)
  • Or scan a single site directly

📝 Output Example

http://site.com | Joomla LFI Multi-Path | lfi | VULNERABLE | http://site.com/index.php?... | db_user:root|db_pass:hackme|db_host:127.0.0.1|db_name:joomla_db|REMOTEDB:YES

  • All results → results_joomla.txt
  • Only vulnerable sites → success_joomla.txt

Other Shells

Mrj Haxcore Bypass 403 Shell
Mrj Haxcore Bypass 403 Shell Download
Gecko Shell Web Backdoor
The Gecko Web Backdoor is a cutting-edge tool designed to bypass various…
Joomla Admin Login Backdoor Shell
Joomla Admin Helper Backdoor is a 100% stealth single-file PHP admin &…
Invisio Backdoor Shell – Hidden Backdoor Bypass Shell 2025
Invisio Phantom Web Shell Stealth Mode WAF Bypass Undetectable Next-Gen Shell “Operate.…
Symlink Buster – Php+JS Symlink Bypass Tools
Symlink Buster – Php Symlink Bypass 🔗 Symlink creation 📁 Auto-generates 24…
Admin Shell Backdoor Command
Command Execution: Execute system-level commands directly from the web interface. WAF Bypass:…
DB Config Hunter
Extracts DB credentials (host, user, pass, db name) in one click. Supports…
Bypass 2024 Priv8 Shell
Bypass 2024 Priv8 Shell