Skip to comments.
Internet is scrambling to fix Log4Shell, the worst hack in history
BGR via msn ^
| 12 December 2021
| Chris Smith
Posted on 12/12/2021 9:08:33 PM PST by blueplum
click here to read article
Navigation: use the links below to view more comments.
first 1-20, 21-31 next last
1
posted on
12/12/2021 9:08:34 PM PST
by
blueplum
To: blueplum
2
posted on
12/12/2021 9:11:47 PM PST
by
ConservativeMind
(Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
To: blueplum
What idiot thought it would be a good idea to have RCE capability in a logging utility?
3
posted on
12/12/2021 9:18:25 PM PST
by
vikingd00d
(chown -R us ~you/base)
To: vikingd00d
It’s not normally there.
This is a vulnerability that makes that happen to the OS.
4
posted on
12/12/2021 9:26:16 PM PST
by
ConservativeMind
(Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
To: ShadowAce
5
posted on
12/12/2021 9:31:26 PM PST
by
Bikkuri
(I am proud to be a PureBlood.)
To: vikingd00d
6
posted on
12/12/2021 9:32:22 PM PST
by
Bikkuri
(I am proud to be a PureBlood.)
To: ConservativeMind
>>It’s not normally there.
Wrong. That “feature” was deliberately coded.
From a different article on it:
The bug, now officially denoted CVE-2021-44228, involves sending a request to a vulnerable server in which you include some data – for example, an HTTP header – that you expect (or know) the server will write to its logfile.
But you booby-trap that data so that the server, while wrangling the data into a format suitable for logging, kicks off a web download as an integral part of constructing the needed log entry.
And not just any old download: if the data that comes back is a valid Java program (a .class file, in the jargon), then the server runs that file to “help” it generate the logging data.
The trick is that, by default, unpatched versions of the Log4j library permit logging requests to trigger general-purpose LDAP (directory services) searches, as well as various other online lookups.
7
posted on
12/12/2021 9:34:28 PM PST
by
vikingd00d
(chown -R us ~you/base)
To: vikingd00d
“The trick is that, by default, unpatched versions of the Log4j library permit logging requests to trigger general-purpose LDAP (directory services) searches, as well as various other online lookups.” You just proved it's not performing remote code execution. There's nothing in Log4j that lets you run any code. It does a lookup, but that is not executed code or arbitrary code.
8
posted on
12/12/2021 9:39:11 PM PST
by
ConservativeMind
(Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
To: ConservativeMind
>>There’s nothing in Log4j that lets you run any code.
Did you miss THIS?
“And not just any old download: if the data that comes back is a valid Java program (a .class file, in the jargon), then the server runs that file to “help” it generate the logging data.”
Downloading and running arbitrary code seems like a bad idea.
9
posted on
12/12/2021 9:44:43 PM PST
by
vikingd00d
(chown -R us ~you/base)
To: vikingd00d
Again, log4j does not ever run such code. It does now, only under an exploit.
10
posted on
12/12/2021 9:50:15 PM PST
by
ConservativeMind
(Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
To: ConservativeMind
Ummmmm... that’s what the entire panic is over. A security flaw means that Log4J will retrieve client-supplied URLs including executing Java code. That’s not good.
To: blueplum
the anethesiologist I sent a few thousand dollars out of pocket to (for about an hours work) just sent a letter informing me that they had a data breach so I should watch out for identity theft
its a wonderful world
https://www.reuters.com/markets/euro...L6cKZXUrr6prI0
12
posted on
12/12/2021 11:22:07 PM PST
by
KTM rider
(The COVID 19 scam is simply TERRORISM )
To: TennesseeProfessor
could this be related ?
https://www.reuters.com/markets/europe/exclusive-imf-10-countries-simulate-cyber-attack-global-financial-system-2021-12-09/?fbclid=IwAR3fiRQ05BTXjvfc5N_hFlNh0yhH5PbmIe8zCzsfzLMw6L6cKZXUrr6prI0
13
posted on
12/12/2021 11:24:50 PM PST
by
KTM rider
(The COVID 19 scam is simply TERRORISM )
To: KTM rider
To: blueplum
We've been at it (fortune 100 company) all weekend 24/7.
We have over 60k VM's with the vulnerability for over 14k applications.
To: vikingd00d
Thnx for providing such a clear explanation for a semi-techie like me!
16
posted on
12/13/2021 1:04:46 AM PST
by
Mr Radical
(In times of universal deceit, telling the truth is a revolutionary act)
To: vikingd00d
I was thinking the same thing. What purpose could it serve?
17
posted on
12/13/2021 1:06:54 AM PST
by
gitmo
(If your theology doesn't become your biography, what good is it?)
To: TexasGunLover
It’s been impossible here to create new ebay listings via desktop since Friday (apparently ok via mobile apps), wonder if there could be a connection?
18
posted on
12/13/2021 1:08:25 AM PST
by
Mr Radical
(In times of universal deceit, telling the truth is a revolutionary act)
To: blueplum
19
posted on
12/13/2021 1:24:37 AM PST
by
GOP Poet
(Super cool you can change your tag line EVERYTIME you post!! :D. (Small things make me happy))
To: Mr Radical
Navigation: use the links below to view more comments.
first 1-20, 21-31 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson