Tomcat
Tomcat Version Enumeration
└─$ curl -s http://megahosting.htb:8080/docs/ | grep Tomcat
<title>Apache Tomcat 9 (9.0.31)Credential Locations
/usr/share/tomcat9/etc/tomcat-users.xml
/etc/tomcat9/tomcat-users.xmlUsername Enum
msf> use auxiliary/scanner/http/tomcat_enumDefault credentials
Password backtrace disclosure
Path Traversal (..;/)
Understanding your role once you have credentials


Text-based manager
Deploy Malicious War
Credential Extraction via JMX
Ghostcat (CVE-2020-1938)
Discovery
Exploitation
Easy Pwns
Apache Tomcat Metasploit
Metasploit Modules
Last updated