ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online

Log4Shell-like security hole found in popular Java SQL database engine H2 - "It's Log4Shell, Jim, but not as we know it." How to find and fix a JNDI-based vuln in th... nakedsecurity.sophos.com/2022/ -2021-42392

#h2 #sql #jndi #java #log4j #vulnerability #cve

Last updated 4 years ago

lars · @ls
179 followers · 3375 posts · Server social.lsnet.eu

Sehr gehässig geschrieben und damit wohl auch durchaus zutreffend...

"Kommentar zu Log4j: Es funktioniert wie spezifiziert"
heise.de/meinung/Kommentar-zu-

#Log4Shell #log4j #java #jndi #Heise

Last updated 4 years ago

Help fuzz various protocols and waits for ping backs Integrates server and payload

github.com/LeakIX/l9fuzz

#ldap #jndi #log4j

Last updated 4 years ago

Cedric · @cedric
374 followers · 1225 posts · Server fosstodon.org

Help fuzz various protocols and waits for ping backs Integrates server and payload

github.com/LeakIX/l9fuzz

#ldap #jndi #log4j

Last updated 4 years ago

AiRolG · @airolgloria
15 followers · 406 posts · Server mastodon.online

a 0-day exploit in the popular Java logging library log4j was discovered that results in Remote Code Execution (RCE) by logging a certain string.
* the impact of the exploit (full server control)
* JDK versions greater than 6u211, 7u201, 8u191, and 11.0.1 are safe
* 2.0 <= Apache log4j <= 2.14.1 are in trouble


lunasec.io/docs/blog/log4j-zer

#update #jndi #rce #apache #p0rz9 #day2 #Java #log4j2

Last updated 4 years ago