-
Enumeration Mandatory Check on the HTTP port 8080 if /manager is accessible (default credentials: tomcat / s3cret or admin / admin). If yes, upload a reverse shell WAR file. Optional Try to brute-force with msf> use scanner/http/tomcat_mgr_login.