pmiaowu/BurpShiroPassiveScan
一款基于BurpSuite的被动式shiro检测插件 observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2240
- days_rel: n/a
- days_push: 1358
- n_releases_24m: 0
Adoption not part of the score
1806 stars · 158 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A passive BurpSuite extension written in Java that automatically detects Apache Shiro framework usage and tests for known Shiro encryption keys (CBC and GCM) on traffic passing through the proxy. It runs per unique domain+port without requiring manual rememberMe cookie manipulation.
Use cases
- detect shiro framework fingerprint during pentests
- find leaked shiro encryption keys passively
- scan burp traffic for shiro deserialization vulnerabilities
- avoid manual rememberMe cookie testing
- check cbc and gcm shiro keys on websites
When to choose
- you are doing authorized penetration testing on Java web apps
- you want passive shiro detection while browsing targets in BurpSuite
- you need fast shiro key brute-forcing without DNSLog callbacks
When to avoid
- you need active scanning outside of BurpSuite
- you target non-Java or non-Shiro applications
- you lack authorization to test the target systems
Facets
plugin · maturity maintenance
security vulnerability-scanning penetration-testing security penetration-testing developer-tools jvm cross-platform burpsuite-extension shiro passive-scanning deserialization security-testing
1 source
- readme: https://github.com/pmiaowu/BurpShiroPassiveScan · fetched 2026-08-28 · 020fa55da5b9
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| pmiaowu/BurpShiroPassiveScan | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="pmiaowu/BurpShiroPassiveScan")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem