
الهدف من هذا المشروع هو توضيح ثغرة الاستغلال log4j cve-2021-44228 في إعداد spring-boot، وإظهار كيفية إصلاحها.
الهدف من هذا المشروع هو توضيح ثغرة الاستغلال log4j cve-2021-44228 في إعداد spring-boot، وإظهار كيفية إصلاحها.
يحتوي هذا المشروع على ثلاث وحدات فرعية. واحدة منها تحتوي على كود ضعيف، والاثنتان الأخريان تم تصحيحهما.
قم بتشغيل ./mvnw clean test في جذر المشروع لتشغيل الاختبارات في كلتا الوحدتين.
في log4shell-example-unpatched، سترى الكثير من الاستثناءات (سيظل الاختبار ناجحًا، لأن هذا متوقع)، لأنه لا يحصل على الاستجابة الصحيحة من الخادم الذي يحاول الاتصال به.
يكون تطبيقك عرضة للثغرة إذا قمت بتجاوز المسجل الافتراضي بحيث يستخدم تنفيذ log4j2 ولم تقم بتجاوز الإصدار المستخدم من log4j2. سيكون ملف pom مشابهًا لما يلي:```xml org.springframework.boot spring-boot-starter org.springframework.boot spring-boot-starter-logging
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-log4j2</artifactId>
</dependency>
يمكنك أن ترى أن استدعاءات السجل لديك أصبحت الآن عرضة للثغرات عن طريق تشغيل الاختبار في `log4shell-example-unpatched`. ينجح هذا الاختبار عندما تكون استدعاءات السجل عرضة للثغرات.
### استخدام اختبار تكامل Spring لمعرفة ما إذا كان تطبيقك الخاص عرضة للثغرات
#### 1. أضف `Log4ShellTest` إلى مشروعك
أضف `Log4ShellTest` من `log4shell-example-patched-version` إلى مشروعك:```java
import lombok.extern.log4j.Log4j2;
import lombok.extern.slf4j.Slf4j;
import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;
import org.junit.jupiter.api.Assertions;
import org.junit.jupiter.api.Test;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.boot.test.context.SpringBootTest;
import org.springframework.context.annotation.ComponentScan;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.annotation.Import;
import org.springframework.stereotype.Component;
import java.io.IOException;
import java.net.ServerSocket;
import java.net.Socket;
import java.util.List;
import java.util.concurrent.CountDownLatch;
import java.util.concurrent.atomic.AtomicInteger;
@SpringBootTest
@Import(Log4ShellTest.Log4ShellConfig.class)
public class Log4ShellTest {
@Autowired
private List<Log4ShellService> servicesToTest;
@Test
public void testVulnerabilityPatched() throws Exception {
CountDownLatch waitLatch = new CountDownLatch(1);
AtomicInteger connectionAttemptCounter = new AtomicInteger();
Thread listener = new Thread(() -> {
try {
ServerSocket socket = new ServerSocket(22345);
while(true) {
waitLatch.countDown();
Socket connection = socket.accept();
connectionAttemptCounter.getAndIncrement();
connection.close();
}
}
catch(IOException ex) {
throw new IllegalStateException(ex);
}
});
listener.start();
waitLatch.await();
servicesToTest.forEach(service -> service.testLog("${jndi:ldap://127.0.0.1:22345}"));
Assertions.assertEquals(0, connectionAttemptCounter.get());
// If you're not using lombok, change the 6 to 2
Assertions.assertEquals(6, servicesToTest.size());
listener.interrupt();
}
@Configuration
@ComponentScan
public static class Log4ShellConfig {
}
public interface Log4ShellService {
void testLog(String arg);
}
@Component
public static class Service1 implements Log4ShellService {
private static final Logger logger = LogManager.getLogger("Test");
@Override
public void testLog(String arg) {
logger.info("Test: " + arg);
}
}
@Component
public static class Service2 implements Log4ShellService {
private static final Logger logger = LogManager.getLogger("Test");
@Override
public void testLog(String arg) {
logger.info("Test: {}", arg);
}
}
// Remove this class if you're not using lombok
@Component
@Slf4j
public static class Service3 implements Log4ShellService {
@Override
public void testLog(String arg) {
log.info("Test: {}", arg);
}
}
// Remove this class if you're not using lombok
@Component
@Slf4j
public static class Service4 implements Log4ShellService {
@Override
public void testLog(String arg) {
log.info("Test: " + arg);
}
}
// Remove this class if you're not using lombok
@Component
@Log4j2
public static class Service5 implements Log4ShellService {
@Override
public void testLog(String arg) {
log.info("Test: {}", arg);
}
}
// Remove this class if you're not using lombok
@Component
@Log4j2
public static class Service6 implements Log4ShellService {
@Override
public void testLog(String arg) {
log.info("Test: " + arg);
}
}
}