Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyยฉ 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution โ€” Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigaciรณn en ciberseguridad, dirigido a demostrar una potencial vulnerabilidad de ejecuciรณn remota de cรณdigo (RCE) en Apache Tomcat (CVE-2025-24813). | Kitploit
Tools/GitHubGitHub/makavellik/poc-cve-2025-24813-apache-tomcat-remote-code-execution
Vulnerability AnalysisExploitationWeb Application ExploitationWAF BypassPenetration TestingLearning & EducationPayload Development
GitHubmakavellik/poc-cve-2025-24813-apache-tomcat-remote-code-execution

POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution

Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigaciรณn en ciberseguridad, dirigido a demostrar una potencial vulnerabilidad de ejecuciรณn remota de cรณdigo (RCE) en Apache Tomcat (CVE-2025-24813).

View Repository
401 year agoNot yet reviewed

Most Popular

View all โ†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools โ†’
Share

Python License MIT Active Stealth Mode Simbiosis


โš ๏ธ๐Ÿš€ CVE-2025-24813 โ€” Apache Tomcat RCE Exploitation Suite

โšก Version: 1.0 ๐Ÿ›ก๏ธ CVE ID: CVE-2025-24813 (Apache Tomcat RCE) ๐Ÿงฌ Payloads: ysoserial / Java ๐ŸŒ Mode: Interactive + Stealth ๐Ÿ”ฌ Usage: Ethical, Investigative, Educational


๐ŸŒŒ Overview

This tool has been designed as a futuristic exploitation suite focused on:

  • ๐Ÿ” Assessing Apache Tomcat against CVE-2025-24813
  • ๐Ÿ› ๏ธ Automating the proof of concept (PoC) process
  • ๐Ÿง  Executing custom payloads with advanced evasion
  • ๐Ÿงฌ Adapting to modern defenses (WAFs, detection, simulated traffic)

๐Ÿงช Designed for cybersecurity professionals, researchers, pentesters, and red teams.


๐Ÿง  What does this script do?

๐Ÿ›ธ Main Features

โœ… Interactive and intuitive interface

โœ… Dynamic payloads (ysoserial or compiled Java)

โœ… Chameleon anti-WAF headers

โœ… Automatic evasion + payload fragmentation

โœ… Backend execution fingerprinting

โœ… Detailed per-target logging

โœ… Dynamic cyberpunk style banner (๐Ÿ”ฎ glitch animation)

โœ… Live console feedback (with Rich & Colorama)


โš™๏ธ Requirements

Install the necessary requirements with:

pip install -r requirements.txt

Dependencies:

requests
colorama
rich
validators

And make sure you have:

  • โ˜• Java and javac in your PATH
  • ๐Ÿ“ฆ ysoserial.jar if you use the ysoserial payload type

๐Ÿงช Usage

Run the script:

python3 POC-Exploit_CVE_2025_24813.py

And fill in the configuration:

๐Ÿงฌ Select payload type ๐Ÿ’ฃ Specify the command ๐ŸŒ Enter the target URL ๐Ÿ”ง Adjust evasion and SSL settings

๐ŸŽฏ Visual Example:

๐Ÿ”— [?] Enter target URL: https://victim.org
๐Ÿ’ฃ [?] Command to execute: whoami
๐Ÿงฌ [?] Payload type: ysoserial
๐Ÿ“‚ [?] Path to ysoserial.jar: ysoserial.jar
๐Ÿ”ง [?] Gadget: CommonsCollections6
๐Ÿ” [?] Verify SSL? (yes/no): no

๐Ÿš€ Executing...
๐Ÿงฌ WAF detected... changing strategy
โš™๏ธ Uploading payload...
๐Ÿ’ฅ Remote execution confirmation
โœ… Result: 'apache'

๐ŸŒˆ Script Visual Architecture

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Interactive Mode            โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  URL Validation              โ”‚
โ”‚  Session Detection           โ”‚
โ”‚  WAF Detection               โ”‚
โ”‚  Payload Generation          โ”‚
โ”‚  Evasive Upload via PUT      โ”‚
โ”‚  Execution Verification      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
        โ†˜ LOGS PER TARGET

๐Ÿงฌ Payload Types

  • ysoserial: Based on the well-known tool ysoserial, it serializes vulnerable gadgets to execute commands.
  • Java Custom: Compiles a custom .java file that executes the remote command from the server.

Common Gadgets:

  • CommonsCollections6
  • Spring1
  • Jdk7u21

๐Ÿ“ Project Structure

POC-Exploit_CVE_2025_24813.py   # Main script
ysoserial.jar               # Required if using 'ysoserial'
logs/                       # Folder for per-target individual logs
payload.ser                 # Temporarily generated payload
Exploit.java / .class       # Temporary Java files

๐Ÿ‘จโ€โš–๏ธ Responsible and Ethical Use

This tool was created for strictly legal and educational purposes.

โœ… Allowed:

  • Authorized security audits
  • Personal labs and testing environments
  • Academic research

๐Ÿšซ Prohibited:

  • Use on third-party systems without consent
  • Illegal or unauthorized activities
  • Distribution with malicious intent

โš–๏ธ Disclaimer

Neither the author nor the contributors are responsible for misuse. You are responsible for your own conduct.


๐Ÿง  Credits

  • ๐Ÿ‘ค Author: [ByMakaveli]
  • ๐Ÿ”ฌ Research: Based on modern Java evasion and exploitation techniques
  • ๐Ÿงฐ Tools used: ysoserial, Java, Rich, Colorama, requests

๐Ÿ›ฐ๏ธ Referenced CVE

๐Ÿ“„ CVE-2025-24813: Apache Tomcat Remote Code Execution ๐Ÿ”— See details at CVE MITRE


๐Ÿ“œ License

MIT License

Copyright (c) 2025

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files...

See the LICENSE file for more information.


๐Ÿ’Ž Visual Inspiration

This README and script are designed for an immersive, visual, and elegant experience, in tune with a new era of futuristic cybersecurity with purpose.

โœจ Not just exploits... it's a technical symphony of evasion and digital control.



๐Ÿ”ง Required Dependencies

1. Python

  • Recommended version: Python 3.8+

  • Python libraries you must install:

    pip install requests colorama
    

2. Java

The script uses two forms of payloads:

  1. Ysoserial โ†’ external Java tool that generates deserialization payloads.
  2. Custom Java compilation โ†’ when you select the "java" option instead of "ysoserial".

Therefore you need:

  • Java JDK (not just JRE, because code is compiled). Verify with:

    java -version
    javac -version
    

    If both commands work, you're ready.


3. Ysoserial

  • Download the .jar from here ๐Ÿ‘‰ https://github.com/frohoff/ysoserial

  • Save it in the same directory as the script or provide the full path when prompted. Example:

    java -jar ysoserial.jar CommonsCollections6 "calc.exe" > test.ser
    

4. Operating System

  • On Windows, the default payload (calc.exe) will open the calculator.
  • On Linux/Mac you can change the command to e.g. gnome-calculator or xcalc.

โš™๏ธ Installation Summary

  1. Install Python 3.8+

  2. Install libraries:

    pip install requests colorama etc
    
  3. Install Java JDK 8+

    java -version
    javac -version
    
  4. Download ysoserial.jar to the script folder.


๐Ÿ‘‰ With all that you can run the script in safe lab mode (only in controlled environments, for testing).


๐Ÿ›ก๏ธ README โ€” Safe Step-by-Step Tutorial

Version: 1.0 Purpose: This guide explains how to prepare a fully safe environment to test the script you have, without affecting real systems. It includes a test server (mock), safe mode (DRY_RUN / SAFE_TEST), and clear steps to run the tool in a lab.


โš ๏ธ Legal and Ethical Notice (READ BEFORE STARTING)

  • Only run in environments under your control: local virtual machines, containers, or isolated networks.
  • Do not run this against third-party systems without explicit written authorization.
  • This guide does not provide steps to exploit real servers. It is intended for defensive and educational testing.

๐Ÿ” What This Tutorial Contains

  1. Setting up the Python environment in isolation.
  2. Creating a test server (mock) that simulates the responses of the target service.
  3. Preparing a dummy payload (harmless) for testing.
  4. Adding a safe mode (SAFE_TEST) to the script so it does not execute external tools or perform dangerous actions.
  5. Step-by-step execution and verification of results (logs).
  6. Automated tests and best practices.

๐Ÿงพ Requirements

  • Python 3.8+ installed.
  • pip available.
  • Recommended: virtualenv or venv.

Install dependencies:

python3 -m venv .venv
source .venv/bin/activate   # Linux / macOS
.\.venv\Scripts\activate  # Windows (PowerShell/Command Prompt)
Download Tool