created: 2025-05-07 23:39
tags:
- shiro
- java安全
Type: Note
aliases:
- Pyke-Shiro
updated: 2025-05-07 23:39
- 先检测密钥(默认为shiro550的密钥),不对可以就可以尝试爆破,爆破不出来就拜拜
- 获取到正确的密钥后,就爆破利用链即可。
- CommonsBeanutilsAttrCompare_183 回显:AllEcho
- CommonsCollections2 回显:AllEcho
- CommonsCollectionsK2 回显:AllEcho
- CommonsBeanutilsString_183 回显:AllEcho
- CommonsBeanutilsAttrCompare_183 回显:TomcatEcho
- CommonsCollections2 回显:TomcatEcho
- CommonsCollectionsK2 回显:TomcatEcho
- CommonsBeanutilsString_183 回显:TomcatEcho