CD's second night
About
Home
Links
Logs
Archives
Categories
Tags
Follow
搜索
About
Home
Links
Logs
Archives
Categories
Tags
Follow
shiro绕过流量检测(rememberme里添加非base64字符如$,!)
SSRF-通过【curl命令】和【gopher协议】对有【SSRF漏洞】的网站远程伪造post请求反弹shell
原理:org.apache.shiro.codec.Base64;中的实现base64Data = discardNonBase64(base64Data);里面的解码有去除垃圾字符的作用
https://www.cnblogs.com/-chenxs/p/11749367.html
Loading...