CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium

A penetration tester has compromised a web server and established a Meterpreter session. The tester identifies that the server is running an outdated version of Apache Tomcat. To establish persistence, the tester plans to deploy a malicious WAR file. Which Metasploit module is best suited for this task?

  1. Aexploit/multi/script/web_delivery
  2. Bauxiliary/scanner/http/tomcat_mgr_login
  3. Cexploit/multi/http/tomcat_mgr_deploy
  4. Dpost/multi/manage/shell_to_meterpreter
Show answer & explanation

Correct answer: C. exploit/multi/http/tomcat_mgr_deploy

The `exploit/multi/http/tomcat_mgr_deploy` module is specifically designed to exploit weak credentials or vulnerabilities in the Tomcat Manager application to deploy a malicious WAR file, which can then be used to establish persistence.

Why the other options are wrong

  • A. This module is for generating and serving payloads for client-side attacks, not for deploying WAR files to Tomcat.
  • B. This is an auxiliary module for brute-forcing Tomcat Manager logins, not for deploying WAR files.
  • D. This module converts a shell session to a Meterpreter session, not for deploying persistence mechanisms.

Tomcat WAR File Deployment for Persistence

Deploying a malicious Web Application Archive (WAR) file to a vulnerable Apache Tomcat server to maintain access or establish a backdoor.

  • Requires access to Tomcat Manager or a vulnerability to upload WAR files.
  • A WAR file can contain a web shell or a reverse shell payload.
  • Metasploit provides modules for automating this process.

Memory trick: Tomcat WARs for persistent web access.

More Post-exploitation and Lateral Movement questions