Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2021-44228] How Bishop Fox Has Been Identifying and Exploiting Log4shell

Summary

Bishop Fox's account of the first chaotic week of Log4shell (CVE-2021-44228): JNDI/LDAP payloads sprayed via HTTP headers and DNS exfiltration when outbound TCP was blocked.
Published
Collected

original ↗

Related coverage

back