log4jscanner
A log4j vulnerability filesystem scanner and Go package for analyzing JAR files. (by google)
local-log4j-vuln-scanner
Simple local scanner for vulnerable log4j instances (by hillu)
log4jscanner | local-log4j-vuln-scanner | |
---|---|---|
20 | 10 | |
1,576 | 381 | |
- | - | |
0.0 | 1.8 | |
almost 2 years ago | almost 2 years ago | |
Go | Go | |
Apache License 2.0 | GNU General Public License v3.0 only |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
log4jscanner
Posts with mentions or reviews of log4jscanner.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-01-03.
-
Activity maintained jars for 1.12
Use PaperBin which OldFag.org uses, and detect log 4j vulnerability using https://github.com/google/log4jscanner/releases
- How does everyone feel about this idea?
- log4j windows scanner?
- google/log4jscanner: A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.
- Google: A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.
- Log4jscanner
- A log4j vulnerability filesystem scanner and Go package for analyzing JAR files open sourced by Google.
local-log4j-vuln-scanner
Posts with mentions or reviews of local-log4j-vuln-scanner.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-01-08.
-
Log4J Network Scanning/Detection on a 100k+ Node Network
The last scanner type is looking for the classes. Carnegie Mellon’s CERTCC released one that is referenced by CISA: https://github.com/CERTCC/CVE-2021-44228_scanner that look for class names and some fingerprints. Then there is a scanner written in Go that checks for the vulnerable class files and their hashes (inside JARs, WARs,EARs, and zips). https://github.com/hillu/local-log4j-vuln-scanner
-
Log4jscanner by Google
I have been scanning with https://github.com/hillu/local-log4j-vuln-scanner and that problem was resolved in there.
-
So how exactly is Log4j supposed to be patched/mitigated on Windows?
If you want to scan your system for vulnerable log4j instances, https://github.com/hillu/local-log4j-vuln-scanner has binaries and is constantly updated
-
All log4j detection tools fail these cases - be careful
We are using this local log4j scanner: https://github.com/hillu/local-log4j-vuln-scanner/
-
Cisco AMP/Endpoint is not a great product for Endpoint Security.
https://github.com/hillu/local-log4j-vuln-scanner - Nope
- Vulnerabilidade Log4j
-
Can PDQ be used to scan for log4j usage?
Log4j may be included in other jars, so a recursive ps scan like https://github.com/hillu/local-log4j-vuln-scanner may come to rescue
-
Any mitigations in the works for the log4j critical CVE?
The scanner provided by https://github.com/hillu/local-log4j-vuln-scanner gives us the following output when using "/opt/qradar/" as directory.
- Log4j 0day being exploited
What are some alternatives?
When comparing log4jscanner and local-log4j-vuln-scanner you can also consider the following projects:
grype - A vulnerability scanner for container images and filesystems
tfsec - Security scanner for your Terraform code