spacer
  • Nmap Security Scanner
    • Intro
    • Ref Guide
    • Install Guide
    • Download
    • Changelog
    • Book
    • Docs
  • Security Lists
    • Nmap Hackers
    • Nmap Dev
    • Bugtraq
    • Full Disclosure
    • Pen Test
    • Basics
    • More
  • Security Tools
    • Pass crackers
    • Sniffers
    • Vuln Scanners
    • Web scanners
    • Wireless
    • Exploitation
    • Packet crafters
    • More
  • Site News
  • Advertising
  • About/Contact
  • Sponsors:

spacer Full Disclosure mailing list archives
spacer   By Date  spacer       spacer   By Thread  spacer      

Apache Tomcat Remote Exploit (PUT request) and Account Scanner
From: "HI-TECH ." <isowarez.isowarez.isowarez () googlemail com>
Date: Sun, 18 Mar 2012 09:42:47 +0100

ISOWAREZ RELEASE
By KINGCOPE - YEAR 2012

-== Apache Tomcat Remote Exploit and Account Scanner ==-

the modified pnscan scanner utility scans a range of IPs to find open
apache tomcat servers
by trying the following login access combinations:

tomcat:tomcat
password:password
admin:admin
admin:password
admin:<nopassword>
tomcat:<nopassword>

the included perl script can be used to unlock apache tomcat servers
remotely by using the collected login combinations.
it will retrieve either a root or SYSTEM reverse shell depending on
the operating system
or the equivalent of a reverse shell as the current user tomcat is running as.
the exploit might contain metasploit logic (thanks to jduck).

Enjoy :>

/Kingcope

www.youtube.com/watch?v=_0wgBHDv3UQ
We are waiting days and nights
for a wind to blow
in this land that has been burnt
and we never get relief

We are waiting days and nights
for the light of that day
that will bring to everyone
relief and an end to the pain, to the war, to the occupation

Attachment: tomcat-remote.zip
Description:

_______________________________________________
Full-Disclosure - We believe in it.
Charter: lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - secunia.com/

spacer   By Date  spacer       spacer   By Thread  spacer

Current thread:
  • Apache Tomcat Remote Exploit (PUT request) and Account Scanner HI-TECH . (Mar 18)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
gipoco.com is neither affiliated with the authors of this page nor responsible for its contents. This is a safe-cache copy of the original web site.