Enumeration
Mandatory
- Check on the HTTP port 8080 if /manager is accessible (default credentials: tomcat / s3cret or admin / admin).
- If yes, upload a reverse shell WAR file.
Optional
- Try to brute-force with
msf> use scanner/http/tomcat_mgr_login.
Leave a Reply
You must be logged in to post a comment.