关联漏洞
描述
This work includes testing and improvement tools for CVE-2021-44228(log4j).
介绍
# ********This work includes testing and improvement tools for CVE-2021-44228(log4j)********
The purpose of this study is to list useful tools that the blue and red team can use against the Log4j vulnerability. Github links bypass tools, scanning, detection mechanisms, etc. can be used for.
**Scanning or POC**
🔴 Title: log4j-shell-poc
🔴 Description: A Proof-Of-Concept for the recently found CVE-2021-44228 vulnerability.
🔴 Url: https://github.com/kozmer/log4j-shell-poc
🔴 Title: Log4j2-RCE
🔴 Description: Log4j2 CVE-2021-44228 Reproduction and echo utilization
🔴 Url: https://github.com/binganao/Log4j2-RCE
🔴 Title: jndi-ldap-test-server
🔴 Description: A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228
🔴 Url: https://github.com/rakutentech/jndi-ldap-test-server
🔴 Title: Logout4Shell
🔴 Description: Use Log4Shell vulnerability to vaccinate a victim server against Log4Shell
🔴 Url: https://github.com/Cybereason/Logout4Shell
🔴 Title: sample-ldap-exploit
🔴 Description: A short demo of CVE-2021-44228
🔴 Url: https://github.com/phoswald/sample-ldap-exploit
🔴 Title: Log4j RCE CVE-2021-44228 Exploitation Detection
🔴 Url: https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b
🔴 Title: Python script to detect if an HTTP server is potentially vulnerable to the log4j 0day RCE
🔴 Url: https://gist.github.com/byt3bl33d3r/46661bc206d323e6770907d259e009b6
🔴 Title: log4j2burpscanner
🔴 Description: CVE-2021-44228, log4j2 burp plug-in Java version, dnslog selected non-dnslog.cn domain names
🔴 Url: https://github.com/f0ng/log4j2burpscanner
🔴 Title: log4shelldetect
🔴 Description: Scans files for .jars potentially vulnerable to Log4Shell (CVE-2021-44228) by inspecting the class paths inside the .jar.
🔴 Url: https://github.com/1lann/log4shelldetect
🔴 Title: Nmap Log4Shell
🔴 Description: Nmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)
🔴 Url: https://github.com/giterlizzi/nmap-log4shell
🔴 Title: LOG4J-POC
🔴 Description: LOG4J batch detection tool -- Red Team Tool -- Essential for net protection -- Redteam --
🔴 Url: https://github.com/XiaoBai-12138/LOG4J-POC
🔴 Title: CVE-2021-44228-PoC-log4j-bypass-words
🔴 Description: CVE-2021-44228 - LOG4J Java exploit - A trick to bypass words blocking patches
🔴 Url: https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words
🔴 Title: Log4Shell Mitigation tester
🔴 Description: Log4Shell CVE-2021-44228 mitigation tester
🔴 Url: https://github.com/lhotari/log4shell-mitigation-tester
🔴 Title: log4j-rce-detect-waf-bypass
🔴 Description: A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads
🔴 Url: https://github.com/toramanemre/log4j-rce-detect-waf-bypass
🔴 Title: jndiRep - CVE-2021-44228
🔴 Description: Scan your logs for CVE-2021-44228 related activity and report the attackers
🔴 Url: https://github.com/js-on/jndiRep
🔴 Title: CVE-2021-44228 checker
🔴 Description: checking for vulnerability CVE-2021-44228
🔴 Url: https://github.com/greymd/CVE-2021-44228
🔴 Title: noPac
🔴 Description: CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter
🔴 Url: https://github.com/cube0x0/noPac
🔴 Title: log4j-scan
🔴 Description: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
🔴 Url: https://github.com/fullhunt/log4j-scan
🔴 Title: CVE-2021-44228-Scanner
🔴 Description: Vulnerability scanner for Log4j2 CVE-2021-44228
🔴 Url: https://github.com/logpresso/CVE-2021-44228-Scanner
🔴 Title: Log4J lab
🔴 Description: A lab for playing around with the Log4J CVE-2021-44228
🔴 Url: https://github.com/tuyenee/Log4shell
🔴 Title: log4j-scanner
🔴 Description: Simple tool for scanning entire directories for attempts of CVE-2021-44228
🔴 Url: https://github.com/kek-Sec/log4j-scanner-CVE-2021-44228
🔴 Title: Log4j-Windows-Scanner
🔴 Description: CVE-2021-44228 vulnerability in Apache Log4j library | Log4j vulnerability scanner on Windows machines.
🔴 Url: https://github.com/Joefreedy/Log4j-Windows-Scanner
🔴 Title: log4j-detector
🔴 Description: Detects Log4J versions on your file-system within any application that are vulnerable to CVE-2021-44228 and CVE-2021-45046. Works on #Linux, #Windows, and #Mac, and everywhere else Java runs, too!
🔴 Url: https://github.com/mergebase/log4j-detector
🔴 Title: Log4JHunt
🔴 Description: An automated, reliable scanner for the Log4Shell CVE-2021-44228 vulnerability
🔴 Url: https://github.com/redhuntlabs/Log4JHunt
🔴 Title: CVE-2021-44228 (Apache Log4j Remote Code Execution)
🔴 Description: The version of 1.x has other vulnerabilities, it is recommended to update to the latest version.
🔴 Url: https://github.com/roxas-tan/CVE-2021-44228
**Defensive Activities**
🔵 Title: log4j-patcher
🔵 Description: Java Agent that disables Apache Log4J's JNDI Lookup. Quick-fix for CVE-2021-44228
🔵 Url: https://github.com/alerithe/log4j-patcher
🔵 Title: CVE-2021-44228 DFIR-Notes
🔵 Url: https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes
🔵 Title: cloudrasp-log4j2
🔵 Description: A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense
🔵 Url: https://github.com/boundaryx/cloudrasp-log4j2
🔵 Title: Minecraft Log4j Honeypot
🔵 Description: Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam
🔵 Url: https://github.com/Adikso/minecraft-log4j-honeypot
🔵 Title: CVE-2021-44228 a.k.a. LOG4J
🔵 Description: This is a public repository from Wortell containing information, links, files and other items related to CVE-2021-44228
🔵 Url: https://github.com/wortell/log4j
🔵 Title: L4J-Vuln-Patch
🔵 Description: This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch
🔵 Url: https://github.com/jacobtread/L4J-Vuln-Patch
🔵 Title: log4j-vulnerability-patcher-agent
🔵 Description: Fixes CVE-2021-44228 in log4j by patching JndiLookup class
🔵 Url: https://github.com/saharNooby/log4j-vulnerability-patcher-agent
🔵 Title: log4jail
🔵 Description: A fast firewall reverse proxy with TLS (HTTPS) and swarm support for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks
🔵 Url: https://github.com/mufeedvh/log4jail
文件快照
[4.0K] /data/pocs/ffd163c8e19ac5184654866e5ae1d8b5d6b5cab5
└── [7.0K] README.md
0 directories, 1 file
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。