log4shell-vulnerable-app
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228). (by christophetd)
log4shell-scanner
Log4Shell scanner for Burp Suite (by PortSwigger)
log4shell-vulnerable-app | log4shell-scanner | |
---|---|---|
5 | 1 | |
1,091 | 48 | |
- | - | |
0.0 | 4.6 | |
8 days ago | 7 months ago | |
Java | Kotlin | |
Apache License 2.0 | GNU General Public License v3.0 only |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
log4shell-vulnerable-app
Posts with mentions or reviews of log4shell-vulnerable-app.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-07-07.
- Finding the "practical" component for my thesis on Log4Shell
- looking for app that is vulnerable to log4j for testing
-
PSA: When there's a 0day, don't trust random people on the internet. Verify everything.
If you aren't sure exactly how this works I recommend trying the log4shell-vulnerable-app and test it yourself with something like dnslog.cn in a controlled/sandboxed environment.
- Log4j Vulnerability Cheatsheet
- Example Spring Boot Application Vulnerable to Log4j RCE
log4shell-scanner
Posts with mentions or reviews of log4shell-scanner.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-07-07.
-
Finding the "practical" component for my thesis on Log4Shell
https://github.com/cisagov/log4j-scanner https://github.com/fullhunt/log4j-scan https://github.com/portswigger/log4shell-scanner
What are some alternatives?
When comparing log4shell-vulnerable-app and log4shell-scanner you can also consider the following projects:
log4j-affected-db - A community sourced list of log4j-affected software
log4j-scan - A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
Log4j-RCE-Scanner - Remote command execution vulnerability scanner for Log4j.
log4jpwn - log4j rce test environment and poc