
Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件
Burpsuite detection plugin for Log4j vulnerability (CVE-2021-44228) Includes ON/OFF switch, Filter, Send
Automatically replace request headers
Automatically replace POST request application/json parameters
Automatically replace POST request application/x-www-urlencoded parameters
Automatically replace GET request parameters
Only replace one parameter per single packet
Added Cookie field detection, sequentially replaces Cookie parameters
Fixed button display anomaly BUG
Updated UI to English

Passively detects all traffic packets passing through Burpsuite, manually sends request packets that need to be detected for detection
Passively detect all traffic packets passing through Burpsuite, and manually send request packets that need to be detected for detection
Use the switch button to choose to turn on or off the scanning function. After turning on, all traffic passing through Burpsuite will be tested for log4j vulnerabilities (BUG occasionally appears here, and the actual switch status is mainly displayed in text)
Use the switch button to choose to turn on or off the scanning function. After turning on, all traffic passing through Burpsuite will be tested for log4j vulnerabilities (BUG occasionally appears here, and the actual switch status is mainly displayed in text)

Filter by entering the domain name, and detect only the domain-related packets that need to be detected
Filter by entering the domain name, and detect only the domain-related packets that need to be detected

Clear the scan list by clicking the "Clear Scan List" button
Clear the scan list by clicking the "Clear Scan List" button

Select the request to be sent and right-click to send it to the log4j Scan plugin for detection
Select the request to be sent and right-click to send it to the log4j Scan plugin for detection

Do not apply the technology or code of this project to illegal purposes such as malicious software production, software copyright/intellectual property theft, or improper profit-making. Implementing the above actions or using this project to perform data sniffing on programs not owned by yourself may violate Article 217 and Article 286 of the Criminal Law of the People's Republic of China, the Cybersecurity Law of the People's Republic of China, the Regulations on the Protection of Computer Software of the People's Republic of China, and other legal provisions. The technology mentioned in this project can only be used in legal scenarios such as private learning and testing. The author of this project is not responsible for any criminal or civil liability arising from improper use of this technology.