shiro绕过流量检测(rememberme里添加非base64字符如$,!)
PHP中在GOT表存放shellcode并执行绕过rasp
原理:org.apache.shiro.codec.Base64;中的实现base64Data = discardNonBase64(base64Data);里面的解码有去除垃圾字符的作用
https://github.com/Mr-xn/Penetration_Testing_POC/blob/master/books/%E9%92%88%E5%AF%B9%E5%AE%9D%E5%A1%94%E7%9A%84RASP%E5%8F%8A%E5%85%B6disable_functions%E7%9A%84%E7%BB%95%E8%BF%87.pdf