Tomcat

Discovery

Via 404 page

Via /docs page

Important Files

WEB-INF/web.xml (deployment descriptor)

  • important to check when leveraging LFI

WEB-INF/classes/ might contain business logics and sensitive information

tomcat-users.xml file is used to allow or disallow access to the /manager and /host-manager

Username Enumeration

Exploitation

Finding login page

Login Bruteforce

Code Execution

Go to /manager/html and upload a war file

Use this webshell for a stealthy approcah https://github.com/SecurityRiskAdvisors/cmd.jsparrow-up-right

Ghostcat (CVE-2020-1938)

versions before 9.0.31, 8.5.51, and 7.0.100

Last updated