You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
1、First, set up a local service and ensure that it can run properly
Find its background login address
2、We can see that remeberMe cipherKey has been written in the source code
3、Inspect the shiro frame using the shiro Blasting tool
4、Once the cipherKey is specified, blow up shiro's utilization chain
5、Discover the construction chain :CommonsBeanutilsString_183 The command output mode is AllEcho
6、The whoami command was successfully executed, confirming the existence of the vulnerability
7、Tool link:https://github.com/SummerSec/ShiroAttack2
The text was updated successfully, but these errors were encountered:
1、First, set up a local service and ensure that it can run properly
Find its background login address
2、We can see that remeberMe cipherKey has been written in the source code
3、Inspect the shiro frame using the shiro Blasting tool
4、Once the cipherKey is specified, blow up shiro's utilization chain
5、Discover the construction chain :CommonsBeanutilsString_183 The command output mode is AllEcho
6、The whoami command was successfully executed, confirming the existence of the vulnerability
7、Tool link:https://github.com/SummerSec/ShiroAttack2
The text was updated successfully, but these errors were encountered: