Skip to content

Latest commit

 

History

History
28 lines (18 loc) · 1.25 KB

File metadata and controls

28 lines (18 loc) · 1.25 KB

Log4Shell

The JNDI features in some versions of the widespread used Apache Log4j 2 logging framework do not protect against attacker controlled LDAP and other JNDI related endpoints. See CVE-2021-44228 and CVE-2021-45046 for more details.

Preconditions and Requirements

For a simple demo you need unguard up and running.

Exploitation with Log4Shell Vulnerability Test Tool

  1. Go to the Log4Shell Vulnerability Test Tool and get a tailored lookup string to be entered into the demo application.
  2. Go to Unguard demo app and login.
  3. Enter the copied string from the test tool above into the Share URL textbox and click post.

unguard-share-url

  1. The test tool will pick up the lookup / GET request for the payload and show the results.

log4shell-demo-results

Further Details

If you want to perform a more sophisticated setup to initiate a reverse shell connection, see this Log4Shell POC.