CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementMedium
A penetration tester has compromised a web server and established a Meterpreter session. The tester identifies that the server is running an outdated version of Apache Tomcat. To establish persistence, the tester plans to deploy a malicious WAR file. Which Metasploit module is best suited for this task?
- Aexploit/multi/script/web_delivery
- Bauxiliary/scanner/http/tomcat_mgr_login
- Cexploit/multi/http/tomcat_mgr_deploy
- Dpost/multi/manage/shell_to_meterpreter
Show answer & explanationAnswer & explanation
Correct answer: C. exploit/multi/http/tomcat_mgr_deploy
The `exploit/multi/http/tomcat_mgr_deploy` module is specifically designed to exploit weak credentials or vulnerabilities in the Tomcat Manager application to deploy a malicious WAR file, which can then be used to establish persistence.
Why the other options are wrong
- A. This module is for generating and serving payloads for client-side attacks, not for deploying WAR files to Tomcat.
- B. This is an auxiliary module for brute-forcing Tomcat Manager logins, not for deploying WAR files.
- D. This module converts a shell session to a Meterpreter session, not for deploying persistence mechanisms.
Tomcat WAR File Deployment for Persistence
Deploying a malicious Web Application Archive (WAR) file to a vulnerable Apache Tomcat server to maintain access or establish a backdoor.
- Requires access to Tomcat Manager or a vulnerability to upload WAR files.
- A WAR file can contain a web shell or a reverse shell payload.
- Metasploit provides modules for automating this process.
Memory trick: Tomcat WARs for persistent web access.