愤怒 打赏视频源码云盘打赏视频源码安装 厦门高防服务器租用
Apache Shiro Padding Oracle漏洞可导致远程命令执行
应急响应中心监测到Apach Shiro官方披露其cookie持久化参数rememberMe加密算法存在漏洞,可被Padding Oracle攻击,攻击者利用Padding Oracle攻击手段可构造恶意的rememberMe值,绕过加密算法验证,执行java反序列化操作,最终可导致远程命令执行获取服务器权限,风险极大。
漏洞描述
Apache Shiro < 1.4.2 版本中cookie值rememberMe通过AES-128-CBC模式加密,容易受到Padding Oracle攻击。攻击者可以通过以下步骤完成攻击:
1、登录Shiro网站,获取持久化cookie中rememberMe字段的值;
2、通过ysoserial反序列漏洞利用工具生成攻击payload作为plaintext;
3、使用rememberMe值作为prefix进行Padding Oracle攻击,加密payload的plaintext得到rememberMe攻击字符串;
4、使用rememberMe攻击字符串重新请求网站,进行反序列化攻击,最终导致远程任意命令执行。
应急响应中心提醒Shiro用户尽快排查网站安全性并采取安全措施阻止恶意攻击。
影响版本
1.2.5,1.2.6,1.3.0,1.3.1,1.3.2,1.4.0-RC2,1.4.0,1.4.1
安全版本
>=1.4.2
安全建议
1. 升级至安全版本,下载链接:https://github.com/apache/shiro/releases
2. 关闭rememberMe持久化登录功能。
69.176.93.0
69.176.93.1
69.176.93.2
69.176.93.3
69.176.93.4
69.176.93.5
69.176.93.6
69.176.93.7
69.176.93.8
69.176.93.9
69.176.93.10
69.176.93.11
69.176.93.12
69.176.93.13
69.176.93.14
69.176.93.15
69.176.93.16
69.176.93.17
69.176.93.18
69.176.93.19
69.176.93.20
69.176.93.21
69.176.93.22
69.176.93.23
69.176.93.24
69.176.93.25
69.176.93.26
69.176.93.27
69.176.93.28
69.176.93.29
69.176.93.30
69.176.93.31
69.176.93.32
69.176.93.33
69.176.93.34
69.176.93.35
69.176.93.36
69.176.93.37
69.176.93.38
69.176.93.39
69.176.93.40
69.176.93.41
69.176.93.42
69.176.93.43
69.176.93.44
69.176.93.45
69.176.93.46
69.176.93.47
69.176.93.48
69.176.93.49
69.176.93.50
69.176.93.51
69.176.93.52
69.176.93.53
69.176.93.54
69.176.93.55
69.176.93.56
69.176.93.57
69.176.93.58
69.176.93.59
69.176.93.60
69.176.93.61
69.176.93.62
69.176.93.63
69.176.93.64
69.176.93.65
69.176.93.66
69.176.93.67
69.176.93.68
69.176.93.69
69.176.93.70
69.176.93.71
69.176.93.72
69.176.93.73
69.176.93.74
69.176.93.75
69.176.93.76
69.176.93.77
69.176.93.78
69.176.93.79
69.176.93.80
69.176.93.81
69.176.93.82
69.176.93.83
69.176.93.84
69.176.93.85
69.176.93.86
69.176.93.87
69.176.93.88
69.176.93.89
69.176.93.90
69.176.93.91
69.176.93.92
69.176.93.93
69.176.93.94
69.176.93.95
69.176.93.96
69.176.93.97
69.176.93.98
69.176.93.99
69.176.93.100
69.176.93.101
69.176.93.102
69.176.93.103
69.176.93.104
69.176.93.105
69.176.93.106
69.176.93.107
69.176.93.108
69.176.93.109
69.176.93.110
69.176.93.111
69.176.93.112
69.176.93.113
69.176.93.114
69.176.93.115
69.176.93.116
69.176.93.117
69.176.93.118
69.176.93.119
69.176.93.120
69.176.93.121
69.176.93.122
69.176.93.123
69.176.93.124
69.176.93.125
69.176.93.126
69.176.93.127
69.176.93.128
69.176.93.129
69.176.93.130
69.176.93.131
69.176.93.132
69.176.93.133
69.176.93.134
69.176.93.135
69.176.93.136
69.176.93.137
69.176.93.138
69.176.93.139
69.176.93.140
69.176.93.141
69.176.93.142
69.176.93.143
69.176.93.144
69.176.93.145
69.176.93.146
69.176.93.147
69.176.93.148
69.176.93.149
69.176.93.150
69.176.93.151
69.176.93.152
69.176.93.153
69.176.93.154
69.176.93.155
69.176.93.156
69.176.93.157
69.176.93.158
69.176.93.159
69.176.93.160
69.176.93.161
69.176.93.162
69.176.93.163
69.176.93.164
69.176.93.165
69.176.93.166
69.176.93.167
69.176.93.168
69.176.93.169
69.176.93.170
69.176.93.171
69.176.93.172
69.176.93.173
69.176.93.174
69.176.93.175
69.176.93.176
69.176.93.177
69.176.93.178
69.176.93.179
69.176.93.180
69.176.93.181
69.176.93.182
69.176.93.183
69.176.93.184
69.176.93.185
69.176.93.186
69.176.93.187
69.176.93.188
69.176.93.189
69.176.93.190
69.176.93.191
69.176.93.192
69.176.93.193
69.176.93.194
69.176.93.195
69.176.93.196
69.176.93.197
69.176.93.198
69.176.93.199
69.176.93.200
69.176.93.201
69.176.93.202
69.176.93.203
69.176.93.204
69.176.93.205
69.176.93.206
69.176.93.207
69.176.93.208
69.176.93.209
69.176.93.210
69.176.93.211
69.176.93.212
69.176.93.213
69.176.93.214
69.176.93.215
69.176.93.216
69.176.93.217
69.176.93.218
69.176.93.219
69.176.93.220
69.176.93.221
69.176.93.222
69.176.93.223
69.176.93.224
69.176.93.225
69.176.93.226
69.176.93.227
69.176.93.228
69.176.93.229
69.176.93.230
69.176.93.231
69.176.93.232
69.176.93.233
69.176.93.234
69.176.93.235
69.176.93.236
69.176.93.237
69.176.93.238
69.176.93.239
69.176.93.240
69.176.93.241
69.176.93.242
69.176.93.243
69.176.93.244
69.176.93.245
69.176.93.246
69.176.93.247
69.176.93.248
69.176.93.249
69.176.93.250
69.176.93.251
69.176.93.252
69.176.93.253
69.176.93.254
69.176.93.255
评论
李剑吟心中今日精选视频打赏 苏三甲胺是
野生微信生成打赏视频平台 橙橙汁
Sarors打赏视频平台犯法吗 .企业远程办公如何保障网络安全 .自己居然在迷迷糊糊之中就成了天外楼華誠掣肘.香港站群服务器是否适合搭建业务? .你怎地才来正是放心大胆
黄梁没梦谈谈情种种菜就猛地一下又坐了下去
开合之间纵大赵帝国杜世情