Hack The Box - JerryPublished November 17, 2018
There's a default Apache Tomcat web page on port 8080. Logging in unsuccessfully gives us example credentials.
Log in with the example credentials. Upload WAR shell. Use shell.
Jerry is dead. Long live Access.
On a more serious note, Jerry was a decent beginner box that suffered the unfortunate problem of perhaps being too easy. A lot of people took advantage of it by changing the login credentials, making life hard for other people who wanted to legitimately get into the box, and in turn welcoming them to HTB with an air of toxicity. To those people: Shame on you.
Thankfully, we now have a few other, perhaps more friendly boxes to recommend to newcomers. For anyone looking for a place to start, Access is well within the reach of a beginner without being painfully easy.