2021-12-13, 12:15 AM
3 Ếch ơi tiêu rồi. Bữa nay phải coi lại trong công ty mình xài log4j Version nào. Rồi viết cái script nhỏ cho comment out hết mấy dòng logger quá. Mình viết program cho openIDM, xài một tỉ dòng logger để debug luôn.
Thôi log vô làm việc cho mau.
Hav' a nice day all. Cầu bằng an.
Critical vulnerability in the popular logging library, Log4j 2, impacts a number of services and applications, including Minecraft, Steam and Apple iCloud. Attackers have begun actively scanning for and attempting to exploit the flaw.
CVE-2021-44228 is a remote code execution (RCE) vulnerability in Apache Log4j 2. An unauthenticated, remote attacker could exploit this flaw by sending a specially crafted request to a server running a vulnerable version of log4j. The crafted request uses a Java Naming and Directory Interface (JNDI) injection via a variety of services including:
In the case of Minecraft, users were able to exploit this vulnerability by sending a specially crafted message through Minecraft chat.
/* src.: https://www.tenable.com/blog/cve-2021-44...nerability
Thôi log vô làm việc cho mau.
Hav' a nice day all. Cầu bằng an.
Critical vulnerability in the popular logging library, Log4j 2, impacts a number of services and applications, including Minecraft, Steam and Apple iCloud. Attackers have begun actively scanning for and attempting to exploit the flaw.
CVE-2021-44228 is a remote code execution (RCE) vulnerability in Apache Log4j 2. An unauthenticated, remote attacker could exploit this flaw by sending a specially crafted request to a server running a vulnerable version of log4j. The crafted request uses a Java Naming and Directory Interface (JNDI) injection via a variety of services including:
- Lightweight Directory Access Protocol (LDAP)
- Secure LDAP (LDAPS)
- Remote Method Invocation (RMI)
- Domain Name Service (DNS)
In the case of Minecraft, users were able to exploit this vulnerability by sending a specially crafted message through Minecraft chat.
/* src.: https://www.tenable.com/blog/cve-2021-44...nerability