
Praktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)
This repository is intended exclusively for educational and demonstration purposes as part of a security-related seminar paper. Do not use this code in production environments or against systems without explicit permission. The setup aims to promote security awareness and show how complex vulnerabilities can arise when seemingly harmless features such as logging, name resolution, and dynamic class loading are combined.
The goal of this seminar paper is to provide an in-depth understanding of the Log4Shell security vulnerability (CVE-2021-44228), which became known in December 2021 and was classified as one of the most critical security vulnerabilities in recent years. The paper explains both the theoretical foundations and provides a practical demonstration of the vulnerability.
For a practical illustration of the Log4Shell security vulnerability, an isolated and containerized environment has been set up in this repository, which reproduces the complete attack chain. The demonstration is based on three central components:
User-Agent header from the HTTP request, which attackers can manipulate to exploit the vulnerability.Exploit.class). Like the LDAP server, this server is under the attacker's control.Note: More detailed information about the setup and execution of the demonstration can be found in sections 4. Project Structure and Setup and 5. Demo of the Project.
Log4Shell is the name of a critical security vulnerability in the Java library Log4j with the identifier CVE-2021-44228. It enables an attacker to execute arbitrary code on a remote server (Remote Code Execution, or RCE) with minimal effort.
The vulnerability affects Log4j versions 2.0 to 2.14.1 and is so severe that it was classified with the highest risk level by many security authorities, including the BSI (German Federal Office for Information Security).
Log4Shell is particularly dangerous because...
The actual cause lies in a feature of Log4j that allows dynamic content to be loaded into log messages through so-called Lookups. In combination with JNDI (Java Naming and Directory Interface) and the LDAP (Lightweight Directory Access Protocol) protocol, this allows remote malicious Java classes to be loaded and executed.
The discovery and publication of the vulnerability triggered a global security wave. Many systems had to be immediately patched or taken offline. In the aftermath, further related vulnerabilities (e.g., CVE-2021-45046) became known, demonstrating how deep and dangerous the problem was.
In the following sections, the technologies involved and their interplay are explained in detail to develop a deeper understanding of the vulnerability.
Log4j is a library created by Apache for logging events in Java applications. Logging is a central tool in software development for monitoring systems or analyzing errors. Log4j is one of the best-known and most widely used logging frameworks in the Java ecosystem and is used in both small applications and large enterprise systems.
While a program runs, events such as the following occur:
These events can be documented with logs, usually as text output to the console, to files, or over network protocols to central log servers. Well-designed logging makes it possible to trace what the application did when.
Log4j provides a flexible, highly configurable infrastructure for generating and processing log messages. Key features include:
DEBUG, INFO, WARN, ERROR) that control how detailed logging should be.Further features relevant to this seminar paper are covered in later sections, particularly the placeholder functionality and lookup functionality.
import org.apache.logging.log4j.LogManager; import org.apache.logging.log4j.Logger;
public class Example { private static final Logger logger = LogManager.getLogger();
public static void main(String[] args) {
logger.info("Starte Anwendung...");
}
}
In this simple example, a logger instance is created or retrieved if it already exists. Then a log message is output at the `INFO` level. Log4j handles the formatting and output of the message based on the configuration. An example configuration could look as follows:```xml
<Configuration status="WARN">
<Appenders>
<Console name="Console" target="SYSTEM_OUT">
<PatternLayout pattern="%d{yyyy-MM-dd HH:mm:ss} %-5p %c{1} - %m%n"/>
</Console>
</Appenders>
<Loggers>
<Root level="info">
<AppenderRef ref="Console"/>
</Root>
</Loggers>
</Configuration>
This configuration defines an appender that outputs log messages in the format Datum Uhrzeit Log-Level Loggername - Nachricht on the console. This appender is then assigned to the root logger, which processes all log messages from level INFO.
The output could then look like this:``` 2023-10-01 12:00:00 INFO Example - Starte Anwendung...
Now let's turn to the specific features of Log4j that are most relevant to the Log4Shell vulnerability.
#### Placeholders in Log Messages