You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
First, build the environment locally to access the backend management system.
You can see that the project's pom.xml file relies on the vulnerable shiro package.
Using ShiroAttack2 Tools for vulnerability detection. Tool link:https://github.com/SummerSec/ShiroAttack2
You can see that Shiro’s secret key was revealed during the explosion.
Detect current Shiro’s exploit chain
The whoami command was executed successfully, confirming that the vulnerability exists
The text was updated successfully, but these errors were encountered:
You can see that Shiro’s secret key was revealed during the explosion.
The text was updated successfully, but these errors were encountered: