@Phantasm_Lab
Open in Telegram
- Red x Blue Security - Bug Bounty 💷 💵 - Exploitable tools - Programming Languages - Malware Analysis Youtube: t.ly/TrGo 🇺🇸 🇧🇷 🇪🇸 since 2017 © Parceiros: @TIdaDepressaoOficial @acervoprivado @ReneGadesx @G4t3w4y
Show more2 974
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
2 974
Log4Shell: RCE 0-day exploit found in log4j 2, a popular Java logging package
On Thursday, December 9th, a 0-day exploit in the popular Java logging library log4j (version 2)
was discovered that results in Remote Code Execution (RCE), by logging a certain string.
Given how ubiquitous this library is, the impact of the exploit (full server control),
and how easy it is to exploit, the impact of this vulnerability is quite severe.
We're calling it "Log4Shell" for short.
The 0-day was tweeted along with a POC posted on GitHub. It has now been published as CVE-2021-44228.
https://www.lunasec.io/docs/blog/log4j-zero-day/2 974
Log4shell Zero-Day Exploit— Full Guide
Hello guys! My name is Tuhin Bose (@tuhin1729). I am currently working as a Chief Information Security Officer and Infosec trainer at DSPH. In this write-up, I am going to describe the critical zero-day vulnerability called Log4Shell that existed in the widely used Java logging library Log4j used by millions of Java applications. So without wasting time, let's start:
https://infosecwriteups.com/log4shell-zero-day-exploit-full-guide-3a505f0c4248
2 974
The Story of an RCE on a Java Web Application
It was about two months ago (November 2021) I was invited to a private program. According to their program scope, I decided to hack them for a while. This post is about a vulnerability I’ve found in this company that led to RCE.
https://infosecwriteups.com/the-story-of-a-rce-on-a-java-web-application-2e400cddcd1e
