module

Apache Tomcat User Enumeration

Disclosed
01/01/1970
Created
05/30/2018

Description

This module enumerates Apache Tomcat's usernames via malformed requests to
j_security_check, which can be found in the web administration package. It should
work against Tomcat servers 4.1.0 - 4.1.39, 5.5.0 - 5.5.27, and 6.0.0 - 6.0.18.
Newer versions no longer have the "admin" package by default. The 'admin' package
is no longer provided for Tomcat 6 and later versions.

Authors

Heyder Andrade Leandro Oliveira

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

    msf > use auxiliary/scanner/http/tomcat_enum
    msf /(m) > show actions
        ...actions...
    msf /(m) > set ACTION < action-name >
    msf /(m) > show options
        ...show and set options...
    msf /(m) > run
  
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.