{"id":13576001,"url":"https://github.com/safe6Sec/ShiroExp","last_synced_at":"2025-04-05T05:30:31.580Z","repository":{"id":40123073,"uuid":"386680702","full_name":"safe6Sec/ShiroExp","owner":"safe6Sec","description":"shiro综合利用工具","archived":false,"fork":false,"pushed_at":"2023-04-15T13:40:44.000Z","size":1269,"stargazers_count":628,"open_issues_count":10,"forks_count":86,"subscribers_count":8,"default_branch":"master","last_synced_at":"2025-04-05T00:05:02.779Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/safe6Sec.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2021-07-16T15:20:11.000Z","updated_at":"2025-04-03T11:15:49.000Z","dependencies_parsed_at":"2024-03-17T05:42:25.067Z","dependency_job_id":"cca2d7ab-20ce-4c64-92b9-3293c50aa1cf","html_url":"https://github.com/safe6Sec/ShiroExp","commit_stats":null,"previous_names":[],"tags_count":5,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe6Sec%2FShiroExp","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe6Sec%2FShiroExp/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe6Sec%2FShiroExp/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/safe6Sec%2FShiroExp/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/safe6Sec","download_url":"https://codeload.github.com/safe6Sec/ShiroExp/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247294011,"owners_count":20915329,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T15:01:06.168Z","updated_at":"2025-04-05T05:30:31.549Z","avatar_url":"https://github.com/safe6Sec.png","language":"Java","funding_links":[],"categories":["Java"],"sub_categories":[],"readme":"##  ShiroExp\n**shiro综合利用工具**\n\n![ShiroExp](https://socialify.git.ci/safe6Sec/ShiroExp/image?description=1\u0026forks=1\u0026issues=1\u0026language=1\u0026owner=1\u0026pulls=1\u0026stargazers=1\u0026theme=Light)\n\n### 0x01 说明\nshiro一把梭工具\n\n目前已知bug：\n1. 程序自带的代理功能bug，不想修。未来也大概率不会修。\n\n### 更新\n\n2022.6.25\n- 添加JRMP功能，可用于手工测试漏洞\n- 修复POST包的bug\n- 修复部分payload suid问题\n- 利用链集成\n- 内存马注入优化\n- 添加AES key自定义功能。在程序当前目录下创建shirokeys.txt即可使用自己的key。\n\n\n\n\n![](img/img_1.png)\n\n![](img/img_2.png)\n\n### 0x02 使用\n1. 先手工判断是否是shiro站点。\n2. 发现有相关特征之后，可以尝试跑一下默认密钥(已经内置主流key,也可以使用自己的key文件。创建shirokey.txt文件放在程序目录)。某些站点rememberMe被改了，需要修改一下特征。也可以开启payload输出，方便复制进行手工检测。一般情况下用SimplePrincipalCollection检测就行，如遇到无回显之类的场景可以尝试用dnslog进行检测。\n3. 拿到密钥之后就可以执行命令或者直接注入内存马。如遇到执行命令无回显，可以更换利用链再次尝试。注入内存马之前，需保证选择的利用链能正常执行命令。\n4. 打点结束，开始下一步。\n\n\n### 0x03 功能\n该轮子主要有三大功能如下:\n- 默认密钥爆破\n  - 利用SimplePrincipalCollection进行检测\n  - 利用dnslog进行检测，以解决无回显rememberMe。使用的是dnslog.cn\n  - 支持高版本的AES-GCM算法\n- 命令执行\n  - 加入了shiro常用的利用链\n  - 加入了两种tomcat通用回显\n- 内存马注入\n  - 冰蝎注入\n\n\n### 0x04 Todo\n1. 加入其他中间件通用回显\n2. 加入更多的内存马注入\n3. 分段传输解决，遇到waf的一些问题\n4. 把filter马换成Listener马\n\n\n\n\n\n### 0x05 参考\np牛的java安全漫谈  \n[一种另类的 shiro 检测方式](https://mp.weixin.qq.com/s?__biz=MzIzOTE1ODczMg==\u0026mid=2247485052\u0026idx=1\u0026sn=b007a722e233b45982b7a57c3788d47d\u0026scene=21#wechat_redirect)  \n[Shiro RememberMe 漏洞检测的探索之路](https://mp.weixin.qq.com/s/jV3B6IsPARRaxetZUht57w)  \n[基于全局储存的新思路 | Tomcat的一种通用回显方法研究](https://mp.weixin.qq.com/s?__biz=MzIwNDA2NDk5OQ==\u0026mid=2651374294\u0026idx=3\u0026sn=82d050ca7268bdb7bcf7ff7ff293d7b3)  \n[Tomcat中一种半通用回显方法](https://xz.aliyun.com/t/7348#toc-0)  \n[基于tomcat的内存 Webshell 无文件攻击技术](https://xz.aliyun.com/t/7388)  \n[Shiro 550 漏洞学习 (二)：内存马注入及回显](http://wjlshare.com/archives/1545)  \n[冰蝎改造之不改动客户端=\u003e内存马](https://mp.weixin.qq.com/s/r4cU84fASjflHrp-pE-ybg)\n[终极Java反序列化Payload缩小技术](https://xz.aliyun.com/t/10824)\n### 0x06 免责声明\n\n本工具仅能在取得足够合法授权的企业安全建设中使用，在使用本工具过程中，您应确保自己所有行为符合当地的法律法规。\n\n如您在使用本工具的过程中存在任何非法行为，您将自行承担所有后果，本工具所有开发者和所有贡献者不承担任何法律及连带责任。\n\n除非您已充分阅读、完全理解并接受本协议所有条款，否则，请您不要安装并使用本工具。\n\n您的使用行为或者您以其他任何明示或者默示方式表示接受本协议的，即视为您已阅读并同意本协议的约束。\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsafe6Sec%2FShiroExp","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsafe6Sec%2FShiroExp","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsafe6Sec%2FShiroExp/lists"}