In this chapter, we covered the basics of Tomcat and read about its architecture and file structure. Then, we moved on to the different techniques for identifying Tomcat and detecting the version number. Next, we looked at the exploitation of Tomcat using the JSP and WAR shell uploads. Toward the end of the chapter, we covered Apache Struts, OGNL, and the exploitation of Tomcat.
In the next chapter, we'll learn how to pen test another famous technological platform—Jenkins.