Apache
Home Directory
Apache may be configured to give users Home directory
FreeBSD Apache
/usr/local/www/apache24/data/
/var/log/httpd-error.log
/var/log/httpd-access.logTomcat
Password is sometimes kept:
Directory where tomcat is installed
Directory starting with tomcat in /etc/
'tomcat-users.xml'
Example: /etc/tomcat7/tomcat-users.xml
Check: cat /etc/passwd .. see where tomcat profile livestomcatWarDeployer
Vuln: Apache Tomcat/7.0.88
REF: JerryHTB
Config Password
Apache James Server 2.3.2
Java Apache Mail Enterprise Server (JAMES)
Open source SMTP and POP3 mail transfer agent and NNTP news server
Default Login: root:root
Connect and Reset user-email password
Then use Thunderbird email to look for clues
Exploit:
Last updated
Was this helpful?