99网
您的当前位置:首页Apache Shiro Padding Oracle Attack (Shiro-721)漏洞复现

Apache Shiro Padding Oracle Attack (Shiro-721)漏洞复现

来源:99网

环境搭建

环境使用centos7+docker

安装git

yum install git

使用dockerfile

启动docker

systemctl start docker

获取dockerfile

git clone https://github.com/3ndz/Shiro-721.git
cd Shiro-721/Docker
docker build -t shiro-721 .
docker run -p 8080:8080 -d shiro-721

查看是否搭建成功

docker ps


访问127.0.0.1:8080查看

centos7+tomcat8

启动docker

systemctl start docker

一系列命令

docker search tomcat
docker pull tomcat
docker run -p 8080:8080 tomcat:latest

https://github.com/jas502n/SHIRO-721中的samples-web-1.4.1.war复制到docker

docker cp samples-web-1.4.1.war 0e9:/opt/tomcat/webapps/

之后打开
http://127.0.0.1:8080/samples-web-1.4.1/login.jsp

登录测试账户抓取cookie


抓取cookie

安装maven

wget https://downloads.apache.org/maven/maven-3/3.6.3/binaries/apache-maven-3.6.3-bin.tar.gz

cd /usr/local
tar -zxvf apache-maven-3.6.3-bin.tar.gz
vi /etc/profile
export MAVEN_HOME=/usr/local/apache-maven-3.6.3
export PATH=$MAVEN_HOME/bin:$PATH 
source /etc/profile
mvn -v 
<mirrors>
    <mirror>
      <id>alimaven</id>
      <name>aliyun maven</name

因篇幅问题不能全部显示,请点此查看更多更全内容