当前位置:网站首页>Log4j 史诗级漏洞,京东这样的大厂都中招了
Log4j 史诗级漏洞,京东这样的大厂都中招了
2022-07-27 16:13:00 【java 分享官】
昨天晚上一个 Apache Log4j2 的高危漏洞被公开了,这个远程代码执行漏洞堪称史诗级别的漏洞。
Apache Log4j2 这个组件有多少公司在用,这个不用我多说吧,实在是太多了。不知道昨晚有多少程序员半夜起床改代码呢?

漏洞原理官方表述是:Apache Log4j2 中存在JNDI注入漏洞,当程序将用户输入的数据进行日志记录时,即可触发此漏洞,成功利用此漏洞可以在目标服务器上执行任意代码。
通俗简单的说就是:在打印日志的时候,如果你的日志内容中包含关键词 ${ ,攻击者就能将关键字所包含的内容当作变量来替换成任何攻击命令,并且执行。

漏洞检测方案
1、通过流量监测设备监控是否有相关 DNSLog 域名的请求
2、通过监测相关日志中是否存在“jndi:ldap://”、“jndi:rmi”等字符来发现可能的攻击行为。
漏洞修复方案
Apache 官方已经发布了测试补丁,中招的用户赶紧升级最新的安全版本吧,
补丁下载:https://github.com/apache/logging-log4j2/releases/tag/log4j-2.15.0-rc1

遇到这种波及范围很广的漏洞,对于白帽子来说简直就是过年了。批量刷漏洞、批量提交漏洞,甲方 SRC 老板们赶紧交米,这一波下来够吃半年~~
圈内已经传出来了,下一个养活安全工程师的洞就是 log4j !

可是就在大家准备提交漏洞的时候,突然发现这漏洞人家不收了!


想想也是,这漏洞已经公开了,再让大家这么提交岂不是浪费自己的预算么。



来源:
https://mp.weixin.qq.com/s/k2LeP612Hdmvyi6LS1qX-g
边栏推荐
- Deep learning: installation package records
- @Considerations for query of convert annotation in JPA
- Deep learning: GCN case
- "Who is Huawei" documentary film series landing on BBC: exposing a large number of Ren Zhengfei's unknown experience
- Zhanrui fresh seedlings: enable full scene applications, and massive data needs the integration of AI and IOT
- Solution to invalid SQL Server connection to server
- uniapp运行到手机(真机调试)
- Deep learning: gat
- Installation and deployment of zabbix6.0
- [MIT 6.S081] Lab 4: traps
猜你喜欢

超实用!阿里P9私藏的Kubernetes学习笔记,看完直呼NB

Solve the problem that reids cannot be accessed by other IPS

Common commands of database 1

File path read
![[MIT 6.S081] Lab 7: Multithreading](/img/f4/26e513fb8678a88cfba29c1a636b37.png)
[MIT 6.S081] Lab 7: Multithreading

Three consecutive high-frequency interview questions of redis online celebrity: cache penetration? Cache breakdown? Cache avalanche?
![[MIT 6.S081] Lec 1: Introduction and examples 笔记](/img/5d/2fc4bde8eebbb22605d314b5292e05.png)
[MIT 6.S081] Lec 1: Introduction and examples 笔记

MySQL学习 Day1 DDL、DML、DQL基础查询

View port PID and end process
![[MIT 6.S081] Lab 3: page tables](/img/ea/94cdb4379733994adf3aa31cf2e826.png)
[MIT 6.S081] Lab 3: page tables
随机推荐
[MIT 6.S081] Lec 3: OS organization and system calls 笔记
rsa加解密(兼容微信小程序环境)
Deep learning: GCN diagram classification case
深度学习:GCN(图卷积神经网络)理论学习总结
机器学习——SVM训练集只有一类标签数据而引发的错误
Linked list storage structure of dynamic linked list 2 stack (linkedstack Implementation)
2021.8.7 note Servlet
MySQL learning day3 multi table query / transaction / DCL
XML learning Day1: XML / jsup parser / selector /xpath selector
[mit 6.s081] LEC 6: isolation & system call entry/exit notes
[MIT 6.S081] Lab 11: networking
[MIT 6.S081] Lec 9: Interrupts 笔记
After being "expelled" from bitland, the Jank group said for the first time: it will return as soon as possible through legal channels!
[MIT 6.S081] Lab 9: file system
Guoju spent $1.8 billion to acquire its competitor KEMET, and the transaction may be completed in the second half of next year
"Who is Huawei" documentary film series landing on BBC: exposing a large number of Ren Zhengfei's unknown experience
MySQL learning Day1 DDL, DML, DQL basic query
Dynamic linked list 4 one-way circular linked list (loopsingle Implementation)
Deep learning: gat
Error launching IDEA