Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2021-44228-waf-tests — Testing WAF protection against CVE-2021-44228 Log4Shell | Kitploit
Tools/GitHubGitHub/robrankin/cve-2021-44228-waf-tests
Defensive ToolsVulnerability ScannersWAF BypassWeb SecurityPenetration Testing
GitHubrobrankin/cve-2021-44228-waf-tests

cve-2021-44228-waf-tests

Testing WAF protection against CVE-2021-44228 Log4Shell

View Repository
44 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Simple bash script to test your WAF or other devices against Log4Shell attack strings and various bypasses

Bypass tricks from: https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

To run:

root@kitploit:~
./cve-2021-44228.sh -t <URL of the target> -c <HTTP Status Code expected>

Or to use the defaults of https://127.0.0.1 and 403:

root@kitploit:~
./cve-2021-44228.sh

For each test string, this will pass the string into a request to the target using various vectors such as:

  • Headers: Using the User-Agent header
  • URI: Appending the string to requested URI
  • Cookies: As the data value of a Cookie
  • Query String: As the value of a query string parameter
  • POST Body Data: As the body data of a POST request

Example output:

root@kitploit:~
Test String: ${jndi:}
-------------------------------------------------------------
HEADERS: curl -ksg -w "%{http_code}" https://127.0.0.1 -A '${jndi:}'
    403
URI: curl -ksg -w "%{http_code}" 'https://127.0.0.1/${jndi:}'
    403
Cookies: curl -ksg -w "%{http_code}" https://127.0.0.1 -b 'session=${jndi:}'
    403
Query String: curl -ksg -w "%{http_code}" 'https://127.0.0.1/something?session=${jndi:}'
    403
POST Data: curl -X POST -ksg -w "%{http_code}" https://127.0.0.1 -d '${jndi:}'
    403
Download Tool