From 1160e517d22e7a29e96363028ad05cdde5aff0bf Mon Sep 17 00:00:00 2001 From: PentesterTN Date: Tue, 17 Mar 2026 04:23:13 -0400 Subject: [PATCH] Merge 41 new Apache Tomcat endpoints into existing wordlist --- .../Web-Content/Web-Servers/Apache-Tomcat.txt | 59 ++++++++++++++++--- 1 file changed, 50 insertions(+), 9 deletions(-) diff --git a/Discovery/Web-Content/Web-Servers/Apache-Tomcat.txt b/Discovery/Web-Content/Web-Servers/Apache-Tomcat.txt index 5f06edd5a..4125f7c9b 100644 --- a/Discovery/Web-Content/Web-Servers/Apache-Tomcat.txt +++ b/Discovery/Web-Content/Web-Servers/Apache-Tomcat.txt @@ -1,9 +1,24 @@ +META-INF +META-INF/ +META-INF/context.xml +RELEASE-NOTES.txt +ROOT +RUNNING.txt +WEB-INF +WEB-INF/ +WEB-INF/classes/ +WEB-INF/web.xml add balancer conf/ conf/server.xml/ dav deploy +docs +docs/ +docs/api +docs/config +docs/setup examples examples/%252e%252e/manager/html examples/%2e%2e/manager/html @@ -11,9 +26,11 @@ examples/../manager/html examples/jsp/index.html examples/jsp/snp/snoop.jsp examples/jsp/source.jsp +examples/servlet/HelloWorldExample +examples/servlet/SnoopServlet +examples/servlet/TroubleShooter examples/servlet/default/jsp/snp/snoop.jsp examples/servlet/default/jsp/source.jsp -examples/servlet/HelloWorldExample examples/servlet/org.apache.catalina.INVOKER.HelloWorldExample examples/servlet/org.apache.catalina.INVOKER.SnoopServlet examples/servlet/org.apache.catalina.INVOKER.TroubleShooter @@ -22,21 +39,35 @@ examples/servlet/org.apache.catalina.servlets.DefaultServlet/jsp/source.jsp examples/servlet/org.apache.catalina.servlets.WebdavServlet/jsp/snp/snoop.jsp examples/servlet/org.apache.catalina.servlets.WebdavServlet/jsp/source.jsp examples/servlet/snoop -examples/servlet/SnoopServlet -examples/servlet/TroubleShooter examples/servlets/index.html +examples/websocket +examples/websocket/index.xhtml host-manager +host-manager/ host-manager/add host-manager/host-manager.xml +host-manager/html host-manager/html/* host-manager/list host-manager/remove host-manager/start host-manager/stop +host-manager/text +host-manager/text/list html/* install j4p +j_security_check?j_username=admin&j_password=admin +j_security_check?j_username=manager&j_password=manager +j_security_check?j_username=tomcat&j_password=tomcat jmxproxy/* +jolokia +jolokia/ +jolokia/exec/java.lang:type=Threading/dumpAllThreads/true/true +jolokia/list +jolokia/read/java.lang:type=Memory +jolokia/read/java.lang:type=Runtime/ClassPath +jolokia/version jsp-examples list manager @@ -48,6 +79,8 @@ manager/html/* manager/install manager/jmxproxy manager/jmxproxy/* +manager/jmxproxy/?get=java.lang:type=Memory&att=HeapMemoryUsage +manager/jmxproxy/?get=java.lang:type=Runtime&att=ClassPath manager/list manager/manager.xml manager/reload @@ -61,16 +94,26 @@ manager/start manager/status manager/status.xsd manager/status/* +manager/status/all +manager/status?XML=true manager/stop manager/text +manager/text/serverinfo +manager/text/sessions?path=/ +manager/text/sslConnectorCiphers +manager/text/threaddump manager/undeploy -RELEASE-NOTES.txt +probe +probe/ +psi-probe +psi-probe/ reload remove resources roles -ROOT save +server-info +server-status serverinfo servlet/default servlet/default/ @@ -91,14 +134,12 @@ sessions shared/ shared/lib/ start +status.xsd status/* stop tomcat-docs undeploy -WEB-INF/ -WEB-INF/classes/ -WEB-INF/web.xml webdav webdav/index.html webdav/servlet/org.apache.catalina.servlets.WebdavServlet/ -webdav/servlet/webdav/ \ No newline at end of file +webdav/servlet/webdav/