CD's second night

shiro绕过流量检测(rememberme里添加非base64字符如$,!)
针对字节hidsderasp模块-通过反射机制修改检测规则
原理:org.apache.shiro.codec.Base64;中的实现base64Data = discardNonBase64(base64Data);里面的解码有去除垃圾字符的作用
https://www.angelwhu.com/paper/2022/02/03/Java_MemoryShell_Elkeid_RASP_Protection/#0x03-Elkeid-RASP%E7%BB%95%E8%BF%87
Loading...