log4jpwn
log4j rce test environment and poc (by leonjza)
log4shell-vulnerable-app
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228). (by christophetd)
log4jpwn | log4shell-vulnerable-app | |
---|---|---|
1 | 5 | |
308 | 1,092 | |
- | - | |
0.0 | 0.0 | |
over 2 years ago | 19 days ago | |
Python | Java | |
GNU General Public License v3.0 only | Apache License 2.0 |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
log4jpwn
Posts with mentions or reviews of log4jpwn.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-12-14.
log4shell-vulnerable-app
Posts with mentions or reviews of log4shell-vulnerable-app.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-07-07.
- Finding the "practical" component for my thesis on Log4Shell
- looking for app that is vulnerable to log4j for testing
-
PSA: When there's a 0day, don't trust random people on the internet. Verify everything.
If you aren't sure exactly how this works I recommend trying the log4shell-vulnerable-app and test it yourself with something like dnslog.cn in a controlled/sandboxed environment.
- Log4j Vulnerability Cheatsheet
- Example Spring Boot Application Vulnerable to Log4j RCE
What are some alternatives?
When comparing log4jpwn and log4shell-vulnerable-app you can also consider the following projects:
Log4j-RCE-Scanner - Remote command execution vulnerability scanner for Log4j.
log4j-affected-db - A community sourced list of log4j-affected software
log4j-scan - A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
log4j-shell-poc - A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
L4sh - Log4Shell RCE Exploit - fully independent exploit does not require any 3rd party binaries.
log4j-finder - Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)
canarytokens - Canarytokens helps track activity and actions on your network.