Remote code execution in Apache Tomcat 7.0
nvd.nist.gov
Remote code execution in Apache Tomcat 7.0
1–10 of 13 posts
Re: Remote code execution in Apache Tomcat 7.0
#2Re: Remote code execution in Apache Tomcat 7.0
#3Re: Remote code execution in Apache Tomcat 7.0
#4It's 2017 and scanning /0 for PUT still reliably gets a bunch of shells...
Re: Remote code execution in Apache Tomcat 7.0
#5It's 2017 and scanning /0 for PUT still reliably gets a bunch of shells...
Why does that return a shell?
Just as common as dorking for common webshells with no or default passwords.
If you need a VPS fast googling for c99 is faster than spinning up something on AWS ;)
Re: Remote code execution in Apache Tomcat 7.0
#6> Please check back again shortly. We apologize for the inconvenience.
> Please direct any questions to nvd@nist.gov. Thank you."
Perfect timing for hn Frontpage. Alt link: https://tomcat.apache.org/security-7.html
Re: Remote code execution in Apache Tomcat 7.0
#7Re: Remote code execution in Apache Tomcat 7.0
#8> "National Vulnerability Database The NVD is currently offline for scheduled maintenance. > Please check back again shortly. We apologize for the inconvenience. > Please direct any questions to nvd@nist.gov. Thank you." Perfect timing for hn Frontpage. Alt link: https://tomcat.apache.org/security-7.html
Re: Remote code execution in Apache Tomcat 7.0
#9Windows only, maybe the title can be changed.
Re: Remote code execution in Apache Tomcat 7.0
#10Earlier quoted context omitted.
Why does that return a shell?
Web shell via put, still quite common. Just as common as dorking for common webshells with no or default passwords. If you need a VPS fast googling for c99 is faster than spinning up something on AWS ;)
Hmm... looks like this dropped from 20k to 700 while I wasn't looking, which I guess is a very good thing (these are DVRs!). But FWIW, for "JAWS/1.0 -2017 -2016" on shodan, then "/shell?whoami" returns "root". :)