
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2017-12615 PUT file upload vulnerability tomcat-pass-getshell weak authentication deployment war package Weak password brute force CVE-2020-1938 Tomcat file read/inclusion
Before first use, please reset the configuration file in settings. For other issues, please read carefully!!! Run with java -jar \*.jar to view the running log information!!
Download the source code and compile with Maven, or directly download from Releases.
Double-click the jar file to run, or execute java -jar AttackTomcat


Use http and socket proxy.

Start the jar file to generate the configuration file config.
AJP vulnerability uses a Python script for verification, requires Python3 environment. Command format: python -V.
Note: If the following prompt appears, it is recommended to directly download AttackTomcat.zip from Releases.

This tool is only for learning exchange, self-testing, prohibits illegal scanning,