akde/infosec

Information security is ultimately about managing risk


Enumeration

Mandatory

  1. Check on the HTTP port 8080 if /manager is acces­si­ble (default cre­den­tials: tom­cat / s3cret or admin / admin).
    1. If yes, upload a reverse shell WAR file.

Optional

  • Try to brute-force with msf> use scanner/http/tomcat_mgr_login.

Leave a Reply

About

Personal collection of some infosec stuff. Primary purpose of this site is to collect and organize for myself.

Note: Some content is not publicly visible due to copyright issues. Therefore, some links could be broken.

Checklists

Categories

Checklists: Ports

python -c 'import pty;pty.spawn("/bin/bash")';

python3 -c 'import pty;pty.spawn("/bin/bash")';