
log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload
Supports RC1 bypass log4j Burp scanning plugin, CVE-2021-44228, supports RC1 bypass, supports JSON data types, supports dnslog.cn and Burp's built-in DNS, can be used with JNDIExploit to generate payloads
Modified based on @pmiaowu's fastjson plugin. The original author used dnslog.cn for outbound checks, but during large-scale offensive and defensive exercises (HW), due to preliminary reconnaissance and testing many sites, dnslog.cn blocks IPs, causing the plugin to fail normal detection.
The base code was completed by @pmiaow. The source code is not provided here.
Result interface
Right-click in Repeater
