Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/bigsizeme/shiro-check

Shiro反序列化回显利用、内存shell、检查 Burp插件
https://github.com/bigsizeme/shiro-check

Last synced: 3 months ago
JSON representation

Shiro反序列化回显利用、内存shell、检查 Burp插件

Awesome Lists containing this project

README

        

# shiro-check

3.0增加了几种回显payload,增加了基于Filter(需要对冰蝎客户端pageContext进行改造)和servlet(部分环境需要把参数据进行URL转码)内存冰蝎的支持。(release提供下载)

2.0增加了回显,及100keys,20keys扫描选项,
利用了burp内置的 dnslog api(Collaborator) 基于ysoserial的Gadgets URLDNS进行DNS查询验证此漏洞!
#release中提供下载
![Alt text](https://github.com/bigsizeme/shiro-check/blob/master/img/shell.png)
![Alt text](https://github.com/bigsizeme/shiro-check/blob/master/img/ZV%605%24%5BAM%7D~LW7Z%24H2316Q%24T.png)

![Alt text](https://github.com/bigsizeme/shiro-check/blob/master/img/check.png)