
Инструкции по быстрому развертыванию Tomcat v9.0.90 с java 25.0.1 2025-10-21 LTS на Windows Server 2019 Standard для ленивых исследователей.
Этот репозиторий содержит понятные инструкции по быстрому развёртыванию Tomcat v9.0.90 с java 25.0.1 2025-10-21 LTS на Windows Server 2019 Standard для упражнений по имитации угроз кибербезопасности. exploit.py использует ysoserial-all.jar для создания полезной нагрузки с помощью модуля CommonsCollections6 из ysoserial-all.jar, которая затем десериализуется зависимостью commons-collections-3.2.1.jar, находящейся в каталоге %CATALINA_HOME%\webapps\ROOT\WEB-INF\lib.
Tomcat v9.0.90:Invoke-WebRequest -Uri "https://archive.apache.org/dist/tomcat/tomcat-9/v9.0.90/bin/apache-tomcat-9.0.90-windows-x64.zip" -OutFile "apache-tomcat-9.0.90-windows-x64.zip"
Expand-Archive -Path "apache-tomcat-9.0.90-windows-x64.zip" -DestinationPath "C:\"
java 25.0.1 2025-10-21 LTS (ZIP-версию):Invoke-WebRequest -Uri "https://download.oracle.com/java/25/archive/jdk-25_windows-x64_bin.zip" -OutFile "jdk-25_windows-x64_bin.zip"
Expand-Archive -Path "jdk-25_windows-x64_bin.zip" -DestinationPath "C:\"
mkdir C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
cd C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
Invoke-WebRequest -Uri "https://repo1.maven.org/maven2/commons-collections/commons-collections/3.2.1/commons-collections-3.2.1.jar" -OutFile "commons-collections-3.2.1.jar"
1. Нажмите «Пуск»
2. Введите «Изменение системных переменных среды»
3. Создайте две новые системные переменные с именами
- `%JAVA_HOME%` со значением `C:\jdk-25.0.1`
- `%CATALINA_HOME%` со значением `C:\apache-tomcat-9.0.90`
4. Измените системную переменную `Path` и добавьте следующие значения:
- `%JAVA_HOME%\bin`
- `%CATALINA_HOME%\bin`
C:\apache-tomcat-9.0.90\bin\service.bat install Tomcat9Server
Set-Service -Name "Tomcat9Server" -StartupType Automatic
Start-Service -Name "Tomcat9Server"
tomcat-users.xml в папке tomcat-9.0.90\conf и добавьте следующее ПЕРЕД </tomcat-users>:<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
context.xml в папке tomcat-9.0.90\conf и замените ВСЁ содержимое следующим:<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- The contents of this file will be loaded for each web application -->
<Context>
<Manager className="org.apache.catalina.session.PersistentManager" maxIdleBackup="1" saveOnRestart="true" processExpiresFrequency="1">
<Store className="org.apache.catalina.session.FileStore"/>
</Manager>
</Context>
web.xml в папке tomcat-9.0.90\conf, найдите DefaultServlet и замените весь блок <servlet></servlet> следующим:<servlet>
<servlet-name>default</servlet-name>
<servlet-class>org.apache.catalina.servlets.DefaultServlet</servlet-class>
<init-param>
<param-name>debug</param-name>
<param-value>0</param-value>
</init-param>
<init-param>
<param-name>listings</param-name>
<param-value>false</param-value>
</init-param>
<init-param>
<param-name>readonly</param-name>
<param-value>false</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
shutdown.bat
startup.bat
New-NetFirewallRule -DisplayName "Tomcat9Server" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow
index.html в C:\tomcat-9.0.90\webapps\ROOT, чтобы сервер выглядел более презентабельно.<Connector port=. Вы можете раскомментировать блок и указать собственный путь к .pfx. Ниже приведён пример добавления cert.pfx в только что созданную папку ssl без пароля для работы через HTTP/1.1:<Connector port="443"
protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150"
SSLEnabled="true"
scheme="https"
secure="true">
<SSLHostConfig>
<Certificate certificateKeystoreFile="C:\tomcat-9.0.90\conf\ssl\cert.pfx"
certificateKeystorePassword=""
certificateKeystoreType="PKCS12" />
</SSLHostConfig>
</Connector>
New-NetFirewallRule -DisplayName "Tomcat9HTTPSServer" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
exploit.pygit clone <this-repo-url>
cd CVE-2025-24813
pip install requests
java --version
curl -L -o ysoserial-all.jar https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar
python exploit.py -t http://<target IP>:8080/ -c "cmd.exe /c calc.exe"
exploit.py в C:\tomcat-9.0.90\webapps\ROOT и C:\tomcat-9.0.90\work\Catalina\localhost\ROOT будут создаваться два файла сессий со случайным именем. Файл .session в рабочей папке должен быть удалён через несколько секунд после выполнения.