Exploiting Java Tomcat With a Crazy JSP Web Shell - Real World CTF 2022 @LiveOverflow
Exploiting Java Tomcat With a Crazy JSP Web Shell - Real World CTF 2022  @LiveOverflow
Uploaded February 2022 | Updated September 2026, 2 weeks ago
This was a hard web CTF challenge involving a JSP file upload with a very restricted character set. We had to use Expression Language (EL) to construct useful primitives and upload an ASCII-only JAR file.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-0day/java-hacking
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Alternative writeups: github.com/voidfyoo/rwctf-4th-desperate-cat/tree/main/writeup
Fuzzing log4j with Jazzer: youtube.com/watch?v=kvREvOvSWt4

CHAPTERS
00:00 - Desperate Cat and the proof-of-work bypass
01:59 - Building the local Tomcat environment
03:12 - Decompiling the WAR and finding /export
04:14 - Restricted JSP upload and Expression Language
05:58 - Team workflow and exploring EL objects
08:35 - Walking Tomcat objects with getters and setters
09:57 - Reflection and fuzzing dead ends
11:26 - StringInterpreter class-loading breakthrough
13:21 - Classloader paths and the URL dead end
14:46 - Uploading a malicious JAR instead
16:19 - False success and forcing a Tomcat reload
18:27 - Crafting an ASCII-only JAR
19:51 - Running the complete exploit
20:28 - Impact and the intended solution

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#CTF #RealWorldCTF #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Exploiting Java Tomcat With a Crazy JSP Web Shell - Real World CTF 2022Public Penetration Test Reports - Learning ResourceMinecraft Reach HackKernel Root Exploit via a ptrace() and execve() Race ConditionExploit Fails? Debug Your Shellcode - bin 0x2BDeepdive Containers - Kernel Sources and nsenterPentesting vs. Bug Bounty vs. Pentesting ???Solving Nintendo HireMe!!! with Basic MathDeveloping GDB Extension for Heap Exploitation | Ep. 12Hacking Google Cloud?The First Exploit  - Pwn2Own Documentary (Part 2)Why Pick sudo as Research Target? | Ep. 01
LiveOverflow |

Exploiting Java Tomcat With a Crazy JSP Web Shell - Real World CTF 2022

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER