Skip to content

CVE-2021-44228 Log4J multithreaded Mass Exploitation tool compatible with URL/IP lists.

Notifications You must be signed in to change notification settings

5l1v3r1/CVE-2021-44228-Mass-RCE

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

63 Commits
 
 

Repository files navigation

CVE-2021-44228-Mass-RCE

CVE-2021-44228 Mass Exploitation tool written in Python 3 compatible with lists of URL/IPs. For a large number of targets you can increase the number of threads, we don't recommend more than 1024. In order to perform command injection (bash/powershell) replace the "payload_cmd" variable inside the file with your code. This download includes a list of over 505,900 potentially vulnerable hosts according to shodan.io and personal scans. This tool is NOT free to prevent abuse and do not expect to find a fix-it-all proof of concept for exploitation for free. Only for those knowledgeable.

Due to lots of requests for we release 4 LAST COPIES: https://satoshidisk.com/pay/CESt4H (3 LEFT)

We put up 4 limited copies for sale, available at: https://satoshidisk.com/pay/CEK4BH (SOLD OUT)

Another updated vulnerable hosts list including over 234,302 will be released to the buyers on 20th of January from our most recent global scan. As of now patches are being applied but the majority of systems aren't patched.

Contact for support and updates: kaiz0r@protonmail.com

Requirements

sudo yum install python3 python3-pip java

ulimit -n 2048

pip3 install queuelib requests

log4js

Statistics

CVE-2021-44228 vulnerability scores a 10 out of 10 on severity scale. The total number of potentially vulnerable devices can be as large as 1 million. In this kit we included a scan of ours coupled with results from SHODAN.IO into a list of over 505,900 hosts that may be vulnerable. The recently released patch has an exploit of in itself, bypass update is included, please email for updates. This vulnerability can take up to 1 year to patch a significant number of hosts.

About

CVE-2021-44228 Log4J multithreaded Mass Exploitation tool compatible with URL/IP lists.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published