
Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.
I am not responsible for your actions, burp-suite freezing, target getting hacked, thermonuclear war, or the current economic crisis caused by you following these directions. YOU are choosing to use this tool, and if you point your finger at me for messing anything up, I will LMAO at you.

Scan Configuration > Select from libraryAudit checks - extensions only and hit OK button.Special thanks to Silent Signal, instructions and scan configurations are inspired from his extension.
[collaborator-server] as a placeholder,[collaborator-server will be replaced by your collaborator server url itself."${jndi:ldap://[collaborator-server]/a}https://github.com/0xDexter0us/Log4J-Scanner/releases/
./gradlew build fatJarbuild/libs/Log4J-Scanner-x.x.x.jarhttps://github.com/f0ng/log4j2burpscannerhttps://github.com/albinowax/ActiveScanPlusPlus & https://github.com/silentsignal/burp-log4shell25 December 2021 - v0.2.0
13 December 2021 - v0.1.0