ShiroAttack2
Test Apache Shiro rememberMe vulnerabilities from GUI or command line
All Skills in This Repository (1)
Pure Emerald Level IndicatorsFrequently Asked Questions
FAQPage SchemaHow to install ShiroAttack2?โผ
Run `npx skills add SummerSec/ShiroAttack2 --all -g -y` in your terminal to install the skill suite globally.
What does ShiroAttack2 do?โผ
It tests Apache Shiro servers for the rememberMe deserialization vulnerability (Shiro-550) by brute-forcing AES keys, executing commands, and injecting memory shells during authorized penetration tests.
Can AI agents run ShiroAttack2 automatically?โผ
Yes. The CLI supports --json structured output and ships a SKILL.md so agents in Claude Code, Cursor, and Codex can run detect, crack, exec, and memshell commands directly.
Does ShiroAttack2 need a graphical interface?โผ
No. It offers both a JavaFX GUI and a full command-line mode that shares the same attack engine, so it works headless on servers.
Is ShiroAttack2 legal to use?โผ
Only for authorized security testing and research with written permission from the target owner. Unauthorized use against systems you do not own is illegal.
Related Repositories in Software Engineering
View All in Software Engineeringโopenclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core