Pyke-Shiro
Pyke-Shiro copied to clipboard
复杂请求下的Shiro反序列化利用工具
利用链爆破问题
大佬为什么利用链爆破就爆破两个链子就不爆破了 
https://github.com/sma11new/Pyke-Shiro/blob/334c46b0a3b5d00c9da154113e7b5e601b2e0666/src/main/java/com/sma11new/exp/shiro/util/ShiroGCM.java#L37 这里用的是shiro1.2.4的cbc加密方式
利用链使用出错 
 
爆破利用链时出错
java -jar Pyke-Shiro_0.3.jar SLF4J: Failed to load class "org.slf4j.impl.StaticLoggerBinder". SLF4J: Defaulting to no-operation (NOP) logger implementation SLF4J: See http://www.slf4j.org/codes.html#StaticLoggerBinder for further details. MLog initialization issue: slf4j found no binding or...
, zy1KJFZ6eucDxK6nGW0xcQ==]Q==7a36 SLF4J: Failed to load class "org.slf4j.impl.StaticLoggerBinder". SLF4J: Defaulting to no-operation (NOP) logger implementation SLF4J: See http://www.slf4j.org/codes.html#StaticLoggerBinder for further details. MLog initialization issue: slf4j found no binding or threatened...
key检测有问题
 原版的shiro4.7可以正常利用