SummerSecSummerSecCommunityยท1 Agent Skills Included

ShiroAttack2

Test Apache Shiro rememberMe vulnerabilities from GUI or command line

Detects and exploits the Apache Shiro rememberMe deserialization flaw (Shiro-550) for authorized security testing. Automates key brute-forcing, gadget chain detection, command execution, and memory shell injection without manual payload crafting. Offers both a JavaFX GUI and a scriptable CLI with JSON output so agents and testers can run full attack workflows faster.
npx skills add SummerSec/ShiroAttack2 --all -g -y
Available:

Tells the AI agent how to build the fat JAR, run the CLI commands (detect, crack, exec, memshell, changekey), and understand the attack architecture when operating this tool.

All Skills in This Repository (1)

Pure Emerald Level Indicators

Frequently Asked Questions

FAQPage Schema
How to install ShiroAttack2?โ–ผ

Run `npx skills add SummerSec/ShiroAttack2 --all -g -y` in your terminal to install the skill suite globally.

What does ShiroAttack2 do?โ–ผ

It tests Apache Shiro servers for the rememberMe deserialization vulnerability (Shiro-550) by brute-forcing AES keys, executing commands, and injecting memory shells during authorized penetration tests.

Can AI agents run ShiroAttack2 automatically?โ–ผ

Yes. The CLI supports --json structured output and ships a SKILL.md so agents in Claude Code, Cursor, and Codex can run detect, crack, exec, and memshell commands directly.

Does ShiroAttack2 need a graphical interface?โ–ผ

No. It offers both a JavaFX GUI and a full command-line mode that shares the same attack engine, so it works headless on servers.

Is ShiroAttack2 legal to use?โ–ผ

Only for authorized security testing and research with written permission from the target owner. Unauthorized use against systems you do not own is illegal.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’