2025Äêjava½Ó¿ÚÔõÑùÈÆ¹ýshiroÉí·ÝÈÏÖ¤£¨2025ÄêjavaÉÏ´«Èƹý£©
shiro·´ÐòÁл¯Â©¶´ÔÀí·ÖÎöÒÔ¼°Â©¶´¸´ÏÖ(Shiro-550/Shiro-721©¶´¸´ÏÖ...
©¶´¸´ÏÖ£ºShiro550©¶´¸´ÏÖ£º »·¾³£ºKali Linux£¬Ê¹ÓÃvulhub/shiro/CVE20164437°Ð³¡¡£ ²½Ö裺 ·ÃÎʰг¡µØÖ·£¬×¥°ü·ÖÎö·µ»Ø°üÖÐÊÇ·ñ´æÔÚrememberMe=deleteMe×ÖÑù£¬È·ÈÏÊÇ·ñÅäÖÃshiro¡£ ʹÓù¤¾ß½øÐÐÃØÔ¿±¬ÆÆ£¬È·ÈÏÀûÓÃÁ´ºÍ»ØÏÔ·½Ê½¡£ Ö´ÐÐÃüÁ·´µ¯shellµÈ²Ù×÷¡£
shiro-550Ö÷ÒªÊÇÓÉshiroµÄrememberMeÄÚÈÝ·´ÐòÁл¯µ¼ÖµÄÃüÁîÖ´ÐЩ¶´£¬Ôì³ÉµÄÔÒòÊÇĬÈϼÓÃÜÃÜÔ¿ÊÇÓ²±àÂëÔÚshiroÔ´ÂëÖУ¬ÈκÎÓÐȨ·ÃÎÊÔ´´úÂëµÄÈ˶¼¿ÉÒÔÖªµÀĬÈϼÓÃÜÃÜÔ¿¡£
¹¥»÷Õß¿ÉÒÔÀûÓÃURLDNSÁ´µÈ¶ñÒâpayload£¬Í¨¹ýһϵÁÐת»»£¬×îÖÕ´¥·¢DNS½âÎöÇëÇó£¬ÒÔ´Ë×÷Ϊ©¶´´æÔÚµÄÅжÏÒÀ¾Ý¡£½øÒ»²½µØ£¬¿ÉÒÔ¹¹ÔìCCÁ´£¬ÓÃÓÚÖ´Ðиü¸´ÔӵĹ¥»÷£¬Èç·´µ¯shellµÈ¡£Shiro·´ÐòÁл¯Â©¶´¸´ÏÖ »·¾³´î½¨£ºÊ¹ÓÃvulhubÌṩµÄShiro»·¾³£¬´î½¨Ò»¸öÒ×Êܹ¥»÷µÄ²âÊÔϵͳ¡£
·¢ËÍÇëÇóÖÁÄ¿±êÍøÕ¾£¬Í¨¹ý²é¿´dnslogÑéÖ¤ÊÇ·ñ³É¹¦·¢ËÍÇëÇó£¬Ö¤Ã÷©¶´´æÔÚ¡£½Ó×Å£¬Éú³ÉCCÁ´£¬ÔÙ´ÎÀûÓÃÏàͬ·½·¨·¢ËÍÇëÇó£¬Ö´Ðз´µ¯shellÃüÁʹÓÃCC6ʵÏÖ£©£¬×¢Òâ°Ð»ú¿ÉÄÜÐèÒªÏÈÉÏ´«nc¹¤¾ß¡£Õë¶Ô²»Í¬°æ±¾µÄShiro£¬Á˽âÆä·´ÐòÁл¯Â©¶´µÄ²îÒì¡£
shiro¼ò½é
1¡¢Shiro¼ò½é ShiroÊÇÒ»¸öJavaµÄ°²È«¿ò¼Ü£¬Ïà¶ÔÓÚSpring Security£¬Shiro¸ü¼ÓÇáÁ¿²¢ÇÒ¼òµ¥¡£Ëü²»½ö¿ÉÒÔÓÃÓÚJavaEE£¬Ò²¿ÉÒÔÓÃÓÚJavaSE£¬Ö÷ÒªÌṩÈÏÖ¤¡¢ÊÚȨ¡¢¼ÓÃÜ¡¢»á»°¹ÜÀí¡¢»º´æµÈ¹¦ÄÜ¡£ShiroÌØÐÔ Shiro²»Ìṩά»¤Óû§/ȨÏ޵ŦÄÜ£¬¶øÊÇͨ¹ýRealmÈÿª·¢Õß×ÔÐÐ×¢ÈëÒÔ¼°Î¬»¤¡£
2¡¢Shiro¿ò¼Ü¼ò½é£ºShiroÊÇÒ»¸ö¿ªÔ´µÄ°²È«¿ò¼Ü£¬ÆäºËÐŦÄܰüÀ¨Éí·ÝÑéÖ¤¡¢ÊÚȨºÍ»á»°¹ÜÀí¡£ÔڵǼ¹ý³ÌÖУ¬Èç¹û¹´Ñ¡Remember meÑ¡ÏShiro»áÉú³ÉÒ»¸öcookie£¬ÓÃÓÚºóÐøµÄÎÞÃÜÂëµÇ¼¡£Â©¶´³ÉÒò£ºµ±·þÎñ¶Ë´¦ÀírememberMe cookieʱ£¬»á¶ÔÆä½øÐжÁÈ¡¡¢´¦ÀíºÍ´æ´¢¡£
3¡¢Shiro Padding Oracle Attack£¨ShiroÌî³äOracle¹¥»÷£©ÊÇÒ»ÖÖÕë¶ÔApache ShiroÉí·ÝÑéÖ¤¿ò¼ÜµÄ°²È«Â©¶´¹¥»÷¡£Apache ShiroÊÇJavaÓ¦ÓóÌÐòÖй㷺ʹÓõÄÉí·ÝÑéÖ¤ºÍÊÚȨ¿ò¼Ü£¬ÓÃÓÚ¹ÜÀíÓû§»á»°¡¢È¨ÏÞÑéÖ¤µÈ¹¦ÄÜ¡£Padding Oracle Attack£¨Ìî³äOracle¹¥»÷£©ÊÇÒ»ÖÖÕë¶Ô¼ÓÃÜË㷨ʹÓÃÌî³äµÄ°²È«Â©¶´¹¥»÷¡£
shiroÊÇʲô
ShiroÊÇÒ»¸öÀ´×Ô±±º£µÀµÄÈÕ±¾Ð¡ÖÚ»¤·ôÆ·ÅÆ£¬ºó·¢Õ¹ÎªÉæ¼°¶à¸ö²úƷϵÁеÄ×ÛºÏÐÔÆ·ÅÆ¡£Æ·ÅÆÆðÔ´Óë¸üÃû£ºShiroµÄǰÉíÃûΪLAUREL£¬µ®ÉúÓÚ2009Äê¡£LAURELһֱרעÓÚÇåÐÂÌìÈ»³É·Ö·Ïߣ¬Ö÷´ò²»Ìí¼Ó»¯Ñ§ÎïÖÊ¡¢º¬Óо«ÓͳɷֵIJúÆ·¡£2015Äê10ÔÂ23ÈÕ£¬LAURELÕýʽ¸üÃûΪShiro£¬²¢ÒÔÆä¼òÔ¼ÐÔÀäµ·çµÄÉè¼ÆÑ¸ËÙÎüÒýÁË´óÁ¿Ïû·ÑÕß¡£
ShiroÊÇÒ»¸öÀ´×Ô±±º£µÀµÄÈÕ±¾Ð¡ÖÚ»¤·ôÆ·ÅÆ£¬ÒÔ¼òÔ¼ÐÔÀäµ·ç¸ñÖø³Æ£¬²úÆ·³É·ÖÌìÈ»£¬²»Ìí¼Ó»¯Ñ§ÎïÖÊ£¬º¬Óо«Óͳɷ֡£ShiroµÄºÃÓòúÆ·°üÀ¨ÉíÌåÈé¡¢»¤ÊÖ˪¡¢¹ÌÌåÏã¸à¡¢³ÖÏãÏ´ÊÖÒº¡¢ÃæÄ¤¡¢Ä¥É°¸àÒÔ¼°Ï´»¤ÏµÁеȡ£
ShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü¡£ËüÌṩÁËÒÔÏÂÖ÷Òª¹¦ÄÜ£ºÈÏÖ¤¹ÜÀí£ºShiro¿ÉÒÔ¹ÜÀíÓû§µÄµÇ¼ºÍµÇ³ö¹ý³Ì£¬ÑéÖ¤Óû§Éí·Ý£¬Ö§³Ö¶àÖÖÈÏÖ¤·½Ê½£¬ÈçÓû§ÃûºÍÃÜÂë¡¢ÁîÅÆ¡¢Ö¤ÊéµÈ¡£
ShiroÊÇApacheÆìÏÂÒ»¸öÇ¿´óµÄJava°²È«¿ò¼Ü£¬Ö÷ÒªÓÃÓÚʵÏÖÓû§Éí·ÝÈÏÖ¤¡¢È¨ÏÞÊÚȨ¡¢¼ÓÃܺͻỰ¹ÜÀíµÈ¹¦ÄÜ¡£Ö÷Òª¹¦ÄÜ£ºÉí·ÝÈÏÖ¤£ºShiro¿ÉÒÔÑéÖ¤Óû§Éí·Ý£¬È·±£Óû§ÊÇËûÃÇËùÉù³ÆµÄÈË¡£ÕâÊÇͨ¹ý±È½ÏÓû§ÌṩµÄƾ֤£¨ÈçÓû§ÃûºÍÃÜÂ룩Óë´æ´¢ÔÚϵͳÖÐµÄÆ¾Ö¤À´ÊµÏֵġ£
ShiroÊÇÒ»¸ö½üÄêÀ´±¸ÊܹØ×¢µÄÆ·ÅÆ£¬Æä¼òÔ¼¶øÓÖÐÔÀäµ·ç¸ñµÄ×°ÐÞºÍÉÌÆ·°ü×°ÎüÒýÁËÖÚ¶àÏû·ÑÕߣ¬°üÀ¨Ðí¶àÅ®ÐÔ¡£ ShiroµÄǰÉíÊÇLAUREL£¬Ò»¸öÆðÔ´ÓÚ±±º£µÀµÄСÖÚ»¤·ôÆ·ÅÆ¡£×Ô2009ÄêÆð£¬LAURELרעÓÚÖÆ×÷ÓëCosme¹ØÁªµÄÉÌÆ·£¬²ÉÓÃÈÕ±¾È«¹úÓÅÖÊÔ²ÄÁÏ£¬ÖÂÁ¦ÓÚ´´Ôì¼ÈÌìÈ»ÓÖ°²È«µÄ»¤·ô²úÆ·¡£
Shiro ÊÇÈÕ±¾ÓïÖеÄÒ»¸ö´Ê»ã£¬Í¨³£±»Àí½âΪ¡°°×É«¡±¡£ËüÊÇÒ»¸öÈÕÓïÃû×Ö»òÐÕÊÏ£¬ÔÚÈÕ±¾µÄһЩµØÇøÒ²ÊÇÒ»¸öÁ÷ÐеÄÃû×Ö¡£³ý´ËÖ®Í⣬Shiro »¹¿ÉÒÔÓÐÆäËûµÄº¬Ò壬±ÈÈç¡°³Ç¡°¡¢¡±Ë¾Áî¡°¡¢¡±Ê×Áì¡°µÈµÈ¡£ÔÚÈÕÓïÖУ¬ÓÉÓÚÒ»¸öºº×Ö¿ÉÒÔÓжàÖÖ¶Á·¨£¬Shiro Õâ¸ö´Ê»ãÒ²¿ÉÒÔÓв»Í¬µÄ·¢Òô·½Ê½¡£
»ùÓÚSSMµÄ½ÌÎñ½Ìѧϵͳ
1¡¢»ùÓÚSSM£¨Spring+SpringMVC+MyBatis£©µÄ½ÌÎñ½ÌѧϵͳÊÇÒ»¸ö²ÉÓÃJava¼¼ÊõÕ»¿ª·¢µÄ½ÌÓý¹ÜÀíÆ½Ì¨£¬½áºÏSpringBootºÍShiro¿ò¼ÜʵÏÖ¸ßЧҵÎñÂß¼´¦Àí¡¢°²È«¿ØÖƼ°¿ìËÙ²¿Êð¡£
2¡¢Ñ§ÁËjavawebÒÔºó¾Í¿ÉÒÔ×Ô¼º×öÒ»¸öÏîÄ¿³öÀ´ ÁË£¬±ÈÈçÄãÏë×öÒ»¸ö¸öÈËÍøÕ¾¡£ Äã¿ÉÒÔ¸øÄãÃÇѧУ×öÒ»¸ö½ÌÎñ¹ÜÀíϵͳ¶¼ÊÇ¿ÉÒԵġ£Spring £ººǫ́¿ò¼Ü¡£ÎªÊ²Ã´ÒªÓÿò¼ÜÄØ£¬¿ÉÒÔ¿ìËÙ¿ª·¢£¬´Ö½µµÍÁËñîºÏ¡£

shiroÖеÄanon,authcɶÒâ˼
1¡¢ShiroÖеÄanon±íʾÄäÃû·ÃÎÊ£¬authc±íʾ»ùÓÚÈÏÖ¤»úÖÆµÄ·ÃÎÊ¿ØÖÆ¡£Ïêϸ½âÊÍÈçÏ£ºanon£ºº¬Ò壺µ±Ä³¸ö×ÊÔ´»ò²Ù×÷±»±ê¼ÇΪanonʱ£¬Òâζ×ÅÕâ¸ö×ÊÔ´»ò²Ù×÷ÔÊÐíÄäÃûÓû§·ÃÎÊ£¬¼´²»ÐèÒª½øÐÐÉí·ÝÑéÖ¤¡£Ó¦Óó¡¾°£ºÍ¨³£ÓÃÓÚÈ·±£Ò»Ð©»ù±¾µÄ¹¦ÄÜ»ò·þÎñ¿ÉÒÔÔÚ²»ÐèÒªµÇ¼µÄÇé¿öÏÂÖ±½ÓʹÓã¬ÀýÈç¼ì²éÒ»¸ö¹«¹²µÄÍøÕ¾Ê×Ò³¡£
2¡¢anon£ºÎÞÐèÈÏÖ¤¼´¿É·ÃÎÊ¡£authc£ºÐèÒªÈÏÖ¤²Å¿É·ÃÎÊ¡£user£ºµã»÷¡°¼ÇסÎÒ¡±¹¦ÄܿɷÃÎÊ¡£
3¡¢ÔÚShiroÖУ¬anon´ú±íÔÊÐíÎÞÈÏÖ¤Ö±½Ó·ÃÎÊ¡£¾ßÌåÀ´Ëµ£ºÎÞÐèÑéÖ¤Éí·Ý£ºÅäÖÃÁËanonµÄ×ÊÔ´»ò½Ó¿Ú£¬ÈκÎÓû§¶¼ÎÞÐè½øÐÐÉí·ÝÑéÖ¤¼´¿É·ÃÎÊ¡£ÕâÒâζ×Å£¬¼´Ê¹ÊÇÒ»¸öδµÇ¼µÄÓû§£¬Ò²¿ÉÒÔ·ÃÎÊÕâЩ×ÊÔ´¡£
4¡¢ÔÚShiroÖУ¬²»Í¬µÄ·ÃÎÊȨÏÞÉèÖÃÓв»Í¬µÄ¹æÔò¡£Ê×ÏÈ£¬anonÔÊÐíÎÞÈÏÖ¤Ö±½Ó·ÃÎÊ£¬Ò²¾ÍÊÇ˵£¬ÈκÎÓû§ÎÞÐèÑéÖ¤Éí·Ý¼´¿É·ÃÎÊÏà¹Ø×ÊÔ´¡£authcÔòÐèÒªÓû§½øÐÐÉí·ÝÑéÖ¤£¬Ö»ÓÐͨ¹ýÑéÖ¤µÄÓû§²ÅÄÜ·ÃÎÊ¡£userÑ¡ÏîÔòÖ§³Ö¼ÇסÎÒ¹¦ÄÜ£¬Óû§¹´Ñ¡ºó£¬Ï´ηÃÎÊʱÎÞÐèÔÙ´ÎÊäÈëÓû§ÃûºÍÃÜÂë¡£
5¡¢ÎÒÊǸöÅÂÂé·³µÄÈË£¬ShiroµÄÅäÖüòµ¥Õâ¾ÍÊÇÎÒÑ¡ÔñµÄÀíÓÉ£¬ºÎ¿öSpring¹Ù·½×Ô¼º¶¼ÍƼöʹÓÃShiro¡£
ÇëÎÊjava¿ª·¢Ò»¸ö²»ÊÇÌØ±ð´óµÄϵͳʱ,ÓбØÒªÓÃsecurityµÈÈÏÖ¤ÊÚȨ...
Ò»°ãÀ´ËµÊ¹ÓÃsecurity×÷ΪȨÏÞ¿ò¼Ü¸ü¾«Ï¸£¬µ«ÊÇÏà±ÈÓÚshiro»¹ÊÇÂÔÏÔ·±ËöÁË£¬shiro¸üСÇɼò±ã£¬Ð¡ÐÍÏîÄ¿µ±ÖУ¬Ã»ÓбØÒªÊ¹ÓÃsecurity£¬µ«ÊÇÖ±½ÓʹÓÃmvcÀ¹½ØÆ÷ÕâÖÖ¹ýʱµÄ¶«Î÷ÓÖ²»ÊǺܰ²È«£¬ËùÒÔÍÆ¼öµÄ¾ÍÊÇ shiro£»Èç¹û»¹Ïë¸ü¼òµ¥¸ü·½±ã£¬ÍƼöʹÓÃsa-token£»¿ÉÒÔ˵ÊÇÅäÖÃ×îÉÙ£¬ÈçͬËüµÄ½éÉÜÒ»Ñù¡£
Ê×ÏÈ£¬Ñ¡Ôñ¿ò¼ÜʱÐèÒª¿¼ÂÇÏîÄ¿µÄ¸´ÔÓÐÔºÍÍŶӵÄÊìϤ³Ì¶È¡£ShiroÓëSpringSecurityÊǹ¦ÄÜÇ¿´óµÄ¿ò¼Ü£¬ËüÃÇÌṩÁ˷ḻµÄ°²È«¹¦ÄÜ£¬Ö§³Ö¸´ÔÓµÄÈÏÖ¤ºÍÊÚȨ²ßÂÔ¡£È»¶ø£¬ÕâÖÖÇ¿´ó±³ºóµÄÊÇѧϰÇúÏß¶¸ÇͺÍÅäÖø´ÔÓ¡£¶ÔÓÚ´ó¹æÄ£¡¢¸´ÔÓÏîÄ¿£¬ÕâÁ½ÖÖ¿ò¼Ü¶¼ÊDz»´íµÄÑ¡Ôñ£¬µ«¶ÔСÐÍ»òÖÐÐÍÏîÄ¿À´Ëµ£¬ËüÃÇ¿ÉÄÜ»áÏԵùýÓÚ¸´ÔÓ¡£
¿ª·¢½¨Òé´ÓС´¦×ÅÊÖ£ºÏÈʵÏÖºËÐŦÄÜ£¬ÔÙÖð²½À©Õ¹¡£´úÂë¹æ·¶£º×ñÑJava±àÂë¹æ·¶£¬±£³Ö´úÂë¿É¶ÁÐÔ¡£²âÊÔÇý¶¯£º±àдµ¥Ôª²âÊԺͼ¯³É²âÊÔ£¬È·±£´úÂëÖÊÁ¿¡£Îĵµ¼Ç¼£º¼Ç¼API½Ó¿Ú¡¢Êý¾Ý¿âÉè¼ÆµÈ¹Ø¼üÐÅÏ¢¡£Í¨¹ýÒÔÉϲ½Ö裬¿Éϵͳ»¯µØÍê³ÉÒ»¸ö»ùÓÚJavaµÄСÐÍÉç½»Ó¦Óÿª·¢¡£
¶¨Î»²»Í¬£º¿ò¼ÜÓëÐÒéµÄ±¾ÖʲîÒìSpring SecurityÊÇÒ»¸ö°²È«¿ò¼Ü£¬ÌṩÍêÕûµÄÉí·ÝÈÏÖ¤ÓëÊÚȨ½â¾ö·½°¸£¬ÊôÓÚÓ¦ÓòãµÄ°²È«¿ØÖƹ¤¾ß¡£¶øOAuth2ÊÇÊÚȨÐÒ飬¶¨ÒåÁ˵ÚÈý·½Ó¦ÓÃÈçºÎ°²È«»ñÈ¡Óû§×ÊÔ´µÄ±ê×¼Á÷³Ì£¬ÊôÓÚÐÒ鹿·¶²ãÃæ¡£