Sploitus

Exploit for ApacheTomcatScanner

kitploit · 2026-09-08

Exploit Code

MARKDOWN160 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-P0DALIRIUS-APACHETOMCATSCANNER
![](https://assets.kitploit.com/production/public/readmes/5548/5e5270d260af6cf947b1f4e42b2fd138984e4d7d56fecd5a20faedb583fcfd1f.png)

一个用于扫描 Apache Tomcat 服务器漏洞的 Python 脚本。   
![PyPI](https://img.shields.io/pypi/v/apachetomcatscanner) ![GitHub release \(latest by date\)](https://img.shields.io/github/v/release/p0dalirius/ApacheTomcatScanner) ![Python pip build](https://github.com/p0dalirius/ApacheTomcatScanner/actions/workflows/python-pip-build.yml/badge.svg) ![](https://img.shields.io/twitter/follow/podalirius_?label=Podalirius&style=social) ![YouTube 频道订阅数](https://img.shields.io/youtube/channel/subscribers/UCF_x5O7CSfr82AfNVTKOv_A?style=social)   


## 功能特性

  * 多线程工作器,用于搜索 Apache Tomcat 服务器。
  * 支持多种目标源: 
    * 通过 LDAP 查询从 Windows 域中检索计算机列表,作为目标列表。
    * 从文件中逐行读取目标。
    * 从 `-tt/--target` 选项读取单个目标(IP/域名/CIDR)。
    * 从 `-tu/--target-url` 选项读取单个目标 URL。
  * 自定义要测试的端口列表。
  * 测试 `/manager/html` 的可访问性。
  * 测试访问 Tomcat Manager 的默认凭据。
  * 使用 `--list-cves` 选项列出每个版本的 CVE,使用 `--show-cves-descriptions` 打印详细的 CVE 描述。



## 安装

现在您可以通过 PyPI 安装它(最新版本是 ![PyPI](https://img.shields.io/pypi/v/apachetomcatscanner)),命令如下:

root@kitploit:~
    
    
    sudo python3 -m pip install apachetomcatscanner
    

## 用法

root@kitploit:~
    
    
    $ ./ApacheTomcatScanner.py -h
    Apache Tomcat Scanner v3.4 - by Remi GASCOU (Podalirius)
    
    usage: ApacheTomcatScanner.py [-h] [-v] [--debug] [-C] [--show-cves-descriptions] [-T THREADS] [-s] [--no-colors] [--only-http] [--only-https] [--export-xlsx EXPORT_XLSX] [--export-json EXPORT_JSON] [--export-sqlite EXPORT_SQLITE]
                                  [-PI PROXY_IP] [-PP PROXY_PORT] [-rt REQUEST_TIMEOUT] [--tomcat-username TOMCAT_USERNAME] [--tomcat-usernames-file TOMCAT_USERNAMES_FILE] [--tomcat-password TOMCAT_PASSWORD]
                                  [--tomcat-passwords-file TOMCAT_PASSWORDS_FILE] [-tf TARGETS_FILE] [-tt TARGET] [-tu TARGET_URL] [-tp TARGET_PORTS] [-ad AUTH_DOMAIN] [-ai AUTH_DC_IP] [-au AUTH_USER] [-ap AUTH_PASSWORD]
                                  [-ah AUTH_HASHES] [--ldaps] [--subnets]
    
    A python script to scan for Apache Tomcat server vulnerabilities.
    
    options:
      -h, --help            show this help message and exit
      -v, --verbose         Verbose mode. (default: False)
      --debug               Debug mode, for huge verbosity. (default: False)
      -C, --list-cves       List CVE ids affecting each version found. (default: False)
      --show-cves-descriptions
                            Show description of found CVEs. (default: False)
      -T THREADS, --threads THREADS
                            Number of threads (default: 250)
      -s, --servers-only    If querying ActiveDirectory, only get servers and not all computer objects. (default: False)
      --no-colors           Disable colored output. (default: False)
      --only-http           Scan only with HTTP scheme. (default: False, scanning with both HTTP and HTTPs)
      --only-https          Scan only with HTTPs scheme. (default: False, scanning with both HTTP and HTTPs)
    
    Export results:
      --export-xlsx EXPORT_XLSX
                            Output XLSX file to store the results in.
      --export-json EXPORT_JSON
                            Output JSON file to store the results in.
      --export-sqlite EXPORT_SQLITE
                            Output SQLITE3 file to store the results in.
    
    Advanced configuration:
      -PI PROXY_IP, --proxy-ip PROXY_IP
                            Proxy IP.
      -PP PROXY_PORT, --proxy-port PROXY_PORT
                            Proxy port
      -rt REQUEST_TIMEOUT, --request-timeout REQUEST_TIMEOUT
                            Set the timeout of HTTP requests.
      --tomcat-username TOMCAT_USERNAME
                            Single tomcat username to test for login.
      --tomcat-usernames-file TOMCAT_USERNAMES_FILE
                            File containing a list of tomcat usernames to test for login
      --tomcat-password TOMCAT_PASSWORD
                            Single tomcat password to test for login.
      --tomcat-passwords-file TOMCAT_PASSWORDS_FILE
                            File containing a list of tomcat passwords to test for login
    
    Targets:
      -tf TARGETS_FILE, --targets-file TARGETS_FILE
                            Path to file containing a line by line list of targets.
      -tt TARGET, --target TARGET
                            Target IP, FQDN or CIDR.
      -tu TARGET_URL, --target-url TARGET_URL
                            Target URL to the tomcat manager.
      -tp TARGET_PORTS, --target-ports TARGET_PORTS
                            Target ports to scan top search for Apache Tomcat servers.
      -ad AUTH_DOMAIN, --auth-domain AUTH_DOMAIN
                            Windows domain to authenticate to.
      -ai AUTH_DC_IP, --auth-dc-ip AUTH_DC_IP
                            IP of the domain controller.
      -au AUTH_USER, --auth-user AUTH_USER
                            Username of the domain account.
      -ap AUTH_PASSWORD, --auth-password AUTH_PASSWORD
                            Password of the domain account.
      -ah AUTH_HASHES, --auth-hashes AUTH_HASHES
                            LM:NT hashes to pass the hash for this user.
      --ldaps               Use LDAPS (default: False)
      --subnets             Get all subnets from the domain and use them as targets (default: False)
    

## 示例

![](https://assets.kitploit.com/production/public/readmes/5548/1f8fbd775a5a7cce5a9e81f6e0c2926e19a5b30e683654e36ae351765a56481e.png)

您还可以使用 `--list-cves` 选项列出每个版本的 CVE:

![](https://assets.kitploit.com/production/public/readmes/5548/829b36ca52e814a1575d9ea7100d479f63005dab3f297b7c8684ce1e958c0e1f.png)

## CVE 数据库自动更新

扫描器包含自动 CVE 数据库更新检查,确保您始终拥有最新的漏洞数据。

### 工作原理

当您运行扫描器时,它会自动检查 CVE 数据库是否超过 30 天。如果已过期,您将看到:

root@kitploit:~
    
    
    [!] CVE 数据库已过期(上次更新:2025-11-01T13:00:00)
    [*] 您可以通过运行以下命令更新:python apachetomcatscanner/data/update_db_nvd.py
    [?] 是否立即更新?这可能需要几分钟。(y/N):
    

输入 `y` 立即更新,或按回车键跳过并继续扫描。

### 禁用自动更新检查

要完全跳过更新检查,请使用 `--no-auto-update` 标志:

root@kitploit:~
    
    
    python ApacheTomcatScanner.py -tt target.com --list-cves --no-auto-update
    

### 手动更新数据库

您可以随时手动更新 CVE 数据库:

root@kitploit:~
    
    
    cd apachetomcatscanner/data
    python update_db_nvd.py
    

**注意:** 更新使用 NVD 官方 API,有速率限制(每 30 秒 5 次请求)。该过程可能需要几分钟,但可以随时中断并恢复。请考虑获取免费的 NVD API 密钥以加快更新速度:https://nvd.nist.gov/developers/request-an-api-key

## 贡献

欢迎提交拉取请求。如果您想添加其他功能,请随时开启一个 issue。