shiro-attack-cli

Detect and verify Shiro-550 rememberMe vulnerabilities via CLI operations.

2.6k|289|Updated Jun 13, 2021
One-click install
npx skills add https://github.com/SummerSec/ShiroAttack2 --skill shiro-attack-cli
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: shiro-attack-cli
Source: https://github.com/SummerSec/ShiroAttack2/tree/main/.claude/skills/shiro-attack-cli
Command: npx skills add https://github.com/SummerSec/ShiroAttack2 --skill shiro-attack-cli

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This CLI-based solution helps security testers quickly detect Shiro rememberMe deserialization vulnerabilities (Shiro-550) and perform controlled testing, key verification, gadget detection, and payload deployment from a single tool.

Core Features & Use Cases

  • Detect Shiro framework presence and vulnerability indicators.
  • Crack or verify the rememberMe AES key across supported modes and versions.
  • Auto-detect gadget chains, execute commands, inject memory shells, and modify keys.
  • Suitable for targeted security assessments of Java applications using Shiro rememberMe.

Quick Start

Launch the CLI against a target URL and choose detect, crack, exec, memshell, or changekey to begin testing.

Frequently Asked Questions about shiro-attack-cli

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect and exploit the Shiro-550 rememberMe deserialization vulnerability?

You can detect and exploit the Shiro-550 rememberMe vulnerability by using a CLI tool to verify framework presence, crack AES keys, and test payload deployments across target Java applications.

Can I crack the Shiro rememberMe AES key and execute commands automatically?

Yes, you can crack the Shiro rememberMe AES key and execute commands automatically by auto-detecting available gadget chains and deploying payloads directly from the CLI interface.

What is the best way to test Shiro rememberMe gadget chains during security assessments?

The best way to test Shiro rememberMe gadget chains is using a CLI tool that auto-detects gadget variants and injects memory shells to validate exploitation paths across diverse Shiro deployments.

Does this Shiro-550 exploitation tool support injecting memory shells and modifying keys?

Yes, this Shiro-550 exploitation tool supports injecting memory shells and modifying keys to verify exploitation paths and validate targeted security assessments of Java applications.

How do I verify Shiro-550 vulnerability indicators across different target applications?

You verify Shiro-550 vulnerability indicators by launching CLI operations to detect framework presence, crack keys, and execute commands across diverse Shiro deployments without needing additional dependencies.