OS Log4 J

Tamarc

VIP Member
VIP Member
Joined
Jul 16, 2010
Messages
2,335
Reaction score
1,450
Location
Scotland
Personaly i dont know too much about this exploit,but from what ive read upto now,i would advise reading up about it, possibly a nasty bug. Not an expert report or anything,just a quick YT Link from a imho safe youtuber.
To view this content we will need your consent to set third party cookies.
For more detailed information, see our cookies page.
 
It's bad because of where/how it's used. It's everywhere sadly, so a lot of entry points to attack/exploit. And even when it got patched, that patch then opened up another way to exploit it. @Grimeire can answer a lot better than I can, he's a Security expert.
 
This log4j is a trivial bit of code and used for logging and not any functionality of the application/system. 100% of systems will use this logging method, are vulnerable thus the score of 10 being given and the criticallity of resolving it.

For me a lot of network devices I implemented and support like Cisco ISE were impacted and within a few days patches were released and implemented.

I implement SIEM solutions and when this got discovered was developing queries in Azure Sentinel to detect any attacks and thankfully none detected

now the fix has exposed a DOS attack

NVD - CVE-2021-45105
 
Last edited:
Back
Top