shiro-attack-cli

Detect and verify Shiro-550 rememberMe vulnerabilities via CLI operations.

2.6k|289|Updated Jun 13, 2021
One-click install
npx skills add https://github.com/SummerSec/ShiroAttack2 --skill shiro-attack-cli
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: shiro-attack-cli
Source: https://github.com/SummerSec/ShiroAttack2/tree/main/.claude/skills/shiro-attack-cli
Command: npx skills add https://github.com/SummerSec/ShiroAttack2 --skill shiro-attack-cli

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This CLI-based solution helps security testers quickly detect Shiro rememberMe deserialization vulnerabilities (Shiro-550) and perform controlled testing, key verification, gadget detection, and payload deployment from a single tool.

Core Features & Use Cases

  • Detect Shiro framework presence and vulnerability indicators.
  • Crack or verify the rememberMe AES key across supported modes and versions.
  • Auto-detect gadget chains, execute commands, inject memory shells, and modify keys.
  • Suitable for targeted security assessments of Java applications using Shiro rememberMe.

Quick Start

Launch the CLI against a target URL and choose detect, crack, exec, memshell, or changekey to begin testing.

Frequently Asked Questions about shiro-attack-cli

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect and exploit the Shiro-550 rememberMe deserialization vulnerability?▼

You can detect and exploit the Shiro-550 rememberMe vulnerability by using a CLI tool to verify framework presence, crack AES keys, and test payload deployments across target Java applications.

Can I crack the Shiro rememberMe AES key and execute commands automatically?▼

Yes, you can crack the Shiro rememberMe AES key and execute commands automatically by auto-detecting available gadget chains and deploying payloads directly from the CLI interface.

What is the best way to test Shiro rememberMe gadget chains during security assessments?▼

The best way to test Shiro rememberMe gadget chains is using a CLI tool that auto-detects gadget variants and injects memory shells to validate exploitation paths across diverse Shiro deployments.

Does this Shiro-550 exploitation tool support injecting memory shells and modifying keys?▼

Yes, this Shiro-550 exploitation tool supports injecting memory shells and modifying keys to verify exploitation paths and validate targeted security assessments of Java applications.

How do I verify Shiro-550 vulnerability indicators across different target applications?▼

You verify Shiro-550 vulnerability indicators by launching CLI operations to detect framework presence, crack keys, and execute commands across diverse Shiro deployments without needing additional dependencies.