Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

shiro-gcm漏洞靶场有bug #1978

Open
pwnhxl opened this issue Sep 7, 2024 · 1 comment
Open

shiro-gcm漏洞靶场有bug #1978

pwnhxl opened this issue Sep 7, 2024 · 1 comment
Labels
bug Something isn't working

Comments

@pwnhxl
Copy link

pwnhxl commented Sep 7, 2024

http://192.168.0.102:8787/shiro/gcm

DQCDO7mdQ3IWD0VxXYBc9Lf45NQSZqYpvsyW1eErrcixmIL9lQauwpzXBy3cGnPsDvtovnH+SJlg0hOqPhnDuN75AWloU+Hm8MTWteu/fKCq4wxxQCBrlrRQRyph+/ajQlqb5TS8zlzQzXcFEixU6EcN6qHaaVzR6T9IXdC7qlEgXYflIavircb64HMK5L0pJswJG1Z92/++Kqb7

Key: 2itfW92XazYRi5ltW0M2yA==

如图 gcm加密模式的靶场只有这个被动插件能检出 其他任何shiro检测工具都检测不出来 并且你们扫描出来的payload 用这个蓝队分析工具也解密不出来了 几个月前我测试的时候不这样的 最新版才有这个bug

shiro-1 shiro-2
@Go0p
Copy link
Collaborator

Go0p commented Sep 9, 2024

感谢反馈,确实有点问题,后续完成修复

@Go0p Go0p added the bug Something isn't working label Sep 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants