Tomcat Discovery & Enumeration
Overview
Tomcat Architecture & Components
Core Directory Structure
Standard Tomcat Installation Layout
Web Application Structure
Standard WAR Application Layout
Critical Configuration Files
web.xml - Deployment Descriptor
tomcat-users.xml - User Authentication
Discovery & Fingerprinting Techniques
HTTP Header Analysis
Method 1: Server Header Detection
Method 2: Error Page Fingerprinting
Method 3: Standard Application Detection
Documentation Page Analysis
/docs Directory Enumeration
Examples Application Analysis
Advanced Fingerprinting Methods
JSP Engine Detection
JVM Information Gathering
Administrative Interface Discovery
Manager Application Enumeration
/manager Interface Discovery
Manager Application Functionality
Host Manager Discovery
Default Credential Testing
Common Tomcat Credentials
Automated Credential Testing
Application and Service Enumeration
Directory and File Discovery
Gobuster Enumeration
Application-Specific Discovery
WAR File and JSP Discovery
JSP Page Enumeration
WAR File Analysis
Configuration File Analysis
tomcat-users.xml Reconnaissance
User and Role Analysis
Security Constraint Analysis
server.xml Analysis
Connector and Port Configuration
Virtual Host Enumeration
HTB Academy Lab Solutions
Lab 1: Tomcat Version Detection
Step 1: Environment Setup
Step 2: Version Detection Methods
Step 3: Expected Answer Extraction
Lab 2: Admin User Role Analysis
Step 1: Configuration File Analysis
Step 2: Role Analysis
Step 3: Role Functionality Understanding
Intelligence Gathering Workflow
Systematic Tomcat Assessment
Phase 1: Discovery & Fingerprinting
Phase 2: Administrative Interface Assessment
Phase 3: Application Analysis
Phase 4: Vulnerability Research
Enterprise Deployment Patterns
Internal Network Reconnaissance
Multi-Instance Discovery
Load Balancer Detection
Development vs Production Discrimination
Environment Identification
Security Assessment Priorities
High-Value Target Identification
EyeWitness Integration
Risk Prioritization
Next Steps
Last updated