# Exploit for WebSocket Vulnerability in Apache Tomcat (CVE-2020-13935)
In the corresponding [blog post](https://blog.redteam-pentesting.de/2020/websocket-vulnerability-tomcat/)
the analysis and exploitation of the vulnerability is explained in detail.
## Usage
Clone the repository, then build the `tcdos` binary. Run the program as follows to test
whether a particular WebSocket endpoint is vulnerable:
```
$ git clone https://github.com/RedTeamPentesting/CVE-2020-13935
$ cd CVE-2020-13935
$ go build
$ ./tcdos [WebSocket endpoint]
```
[4.0K] /data/pocs/0039ddd728a57b14a176fd6952f5e9bffb979459
├── [ 67] go.mod
├── [ 175] go.sum
├── [1.0K] LICENSE
├── [7.1K] main.go
├── [ 543] README.md
└── [ 323] wsDemon.sh
0 directories, 6 files