
Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigaciรณn en ciberseguridad, dirigido a demostrar una potencial vulnerabilidad de ejecuciรณn remota de cรณdigo (RCE) en Apache Tomcat (CVE-2025-24813).
โก Version: 1.0 ๐ก๏ธ CVE ID: CVE-2025-24813 (Apache Tomcat RCE) ๐งฌ Payloads:
ysoserial/Java๐ Mode: Interactive + Stealth ๐ฌ Usage: Ethical, Investigative, Educational
This tool has been designed as a futuristic exploitation suite focused on:
๐งช Designed for cybersecurity professionals, researchers, pentesters, and red teams.
โ Interactive and intuitive interface
โ
Dynamic payloads (ysoserial or compiled Java)
โ Chameleon anti-WAF headers
โ Automatic evasion + payload fragmentation
โ Backend execution fingerprinting
โ Detailed per-target logging
โ Dynamic cyberpunk style banner (๐ฎ glitch animation)
โ Live console feedback (with Rich & Colorama)
Install the necessary requirements with:
pip install -r requirements.txt
Dependencies:
requests
colorama
rich
validators
And make sure you have:
Java and javac in your PATHysoserial.jar if you use the ysoserial payload typeRun the script:
python3 POC-Exploit_CVE_2025_24813.py
And fill in the configuration:
๐งฌ Select payload type ๐ฃ Specify the command ๐ Enter the target URL ๐ง Adjust evasion and SSL settings
๐ [?] Enter target URL: https://victim.org
๐ฃ [?] Command to execute: whoami
๐งฌ [?] Payload type: ysoserial
๐ [?] Path to ysoserial.jar: ysoserial.jar
๐ง [?] Gadget: CommonsCollections6
๐ [?] Verify SSL? (yes/no): no
๐ Executing...
๐งฌ WAF detected... changing strategy
โ๏ธ Uploading payload...
๐ฅ Remote execution confirmation
โ
Result: 'apache'
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Interactive Mode โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ URL Validation โ
โ Session Detection โ
โ WAF Detection โ
โ Payload Generation โ
โ Evasive Upload via PUT โ
โ Execution Verification โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ LOGS PER TARGET
ysoserial, it serializes vulnerable gadgets to execute commands..java file that executes the remote command from the server.CommonsCollections6Spring1Jdk7u21POC-Exploit_CVE_2025_24813.py # Main script
ysoserial.jar # Required if using 'ysoserial'
logs/ # Folder for per-target individual logs
payload.ser # Temporarily generated payload
Exploit.java / .class # Temporary Java files
This tool was created for strictly legal and educational purposes.
โ Allowed:
๐ซ Prohibited:
Neither the author nor the contributors are responsible for misuse. You are responsible for your own conduct.
ysoserial, Java, Rich, Colorama, requests๐ CVE-2025-24813: Apache Tomcat Remote Code Execution ๐ See details at CVE MITRE
MIT License
Copyright (c) 2025
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files...
See the
LICENSEfile for more information.
This README and script are designed for an immersive, visual, and elegant experience, in tune with a new era of futuristic cybersecurity with purpose.
โจ Not just exploits... it's a technical symphony of evasion and digital control.
Recommended version: Python 3.8+
Python libraries you must install:
pip install requests colorama
The script uses two forms of payloads:
Therefore you need:
Java JDK (not just JRE, because code is compiled). Verify with:
java -version
javac -version
If both commands work, you're ready.
Download the .jar from here ๐ https://github.com/frohoff/ysoserial
Save it in the same directory as the script or provide the full path when prompted. Example:
java -jar ysoserial.jar CommonsCollections6 "calc.exe" > test.ser
calc.exe) will open the calculator.gnome-calculator or xcalc.Install Python 3.8+
Install libraries:
pip install requests colorama etc
Install Java JDK 8+
java -version
javac -version
Download ysoserial.jar to the script folder.
๐ With all that you can run the script in safe lab mode (only in controlled environments, for testing).
Version: 1.0 Purpose: This guide explains how to prepare a fully safe environment to test the script you have, without affecting real systems. It includes a test server (mock), safe mode (DRY_RUN / SAFE_TEST), and clear steps to run the tool in a lab.
pip available.virtualenv or venv.Install dependencies:
python3 -m venv .venv
source .venv/bin/activate # Linux / macOS
.\.venv\Scripts\activate # Windows (PowerShell/Command Prompt)