Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

LOG4J检测 #7

Closed
xiaobaixuexi111 opened this issue Oct 17, 2022 · 5 comments
Closed

LOG4J检测 #7

xiaobaixuexi111 opened this issue Oct 17, 2022 · 5 comments

Comments

@xiaobaixuexi111
Copy link

师傅,log4j需要设置反连吗,还是直接扫就行了,为啥-u没扫出来

@u21h2
Copy link
Owner

u21h2 commented Oct 17, 2022

默认设的是ceye的反连 你手动打ceye能打出来吗?

@xiaobaixuexi111
Copy link
Author

我是直接下载下来用的,需要配置什么东西吗?那个站点是靶场,手测 log4j2 都是有的

@u21h2
Copy link
Owner

u21h2 commented Oct 17, 2022

vulhub之类的吧 靶场信息发一下我看看

@xiaobaixuexi111
Copy link
Author

@u21h2
Copy link
Owner

u21h2 commented Oct 17, 2022

看了下这个是post的body里的jndi注入点 暂时还不支持这种 只支持常见请求头的 可以试一下
https://vulfocus.cn/#/dashboard?image_id=3321e635-921d-4d28-8f93-a7c03fd9aa5b

@u21h2 u21h2 closed this as completed Oct 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants