Ross ROSS = Recommend OSS · open-source software intelligence for agents

SummerSec/ShiroAttack2

shiro反序列化漏洞综合利用(仅限授权测试使用) observed · 2026-08-28

github.com/SummerSec/ShiroAttack2 · Java · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

88/100

  • Activity 85
  • Release rhythm 86
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 12.5
  • age_days: 1907
  • days_rel: 98
  • days_push: 90
  • n_releases_24m: 5

Full methodology

Adoption not part of the score

2619 stars · 290 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Java-based exploitation tool for the Apache Shiro-550 rememberMe deserialization vulnerability, offering both a JavaFX GUI and a CLI. It detects Shiro targets, brute-forces AES keys, executes commands via gadget chains, injects memshells, and replaces target keys, intended only for authorized testing.

Use cases

  • detect whether a target web app uses Apache Shiro
  • brute-force or verify the Shiro rememberMe AES key
  • execute OS commands on an authorized Shiro-550 target
  • inject a memshell like Godzilla or Behinder into a Shiro app
  • replace a target's Shiro AES key to invalidate old ones
  • script Shiro exploitation in CI or AI agent workflows with JSON output

When to choose

  • you are doing authorized penetration testing against Shiro-550 targets
  • you need both GUI and scriptable CLI exploitation of Shiro deserialization
  • you want automatic gadget chain detection without commons-collections dependencies

When to avoid

  • you lack explicit authorization to test the target
  • you need a general-purpose vulnerability scanner rather than a Shiro-specific exploit tool
  • your target runs a patched Shiro version with a strong random key

Facets

cli-tool · maturity active

penetration-testing security cli security penetration-testing cross-platform jvm cli shiro shiro-550 deserialization exploitation memshell java-security red-team authorized-testing

1 source

Member repositories

RepositoryRoleHealth v2
SummerSec/ShiroAttack2main88

For agents

markdown · JSON · MCP: product_card(name="SummerSec/ShiroAttack2")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem