
CVE-2021-44228-white-box
Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting…

Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting…

The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.

Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)

A vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105

vulnerable setup to display an attack chain of log4j CVE-2021-44228 with privilege escalation to root using the polkit exploit CVE-2021-4034

Step-by-step tutorial for exploiting Log4j CVE-2021-44228 with Docker-based vulnerable app, JNDIExploit listener, and LDAP payload injection for…

Java-based test environment for CVE-2021-44228 (Log4Shell) vulnerability. Provides a local endpoint to validate and experiment with the Log4j remote…

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228

Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45105 with documented exploitation steps and mitigation guidance for security…

Sample Spring Boot application intentionally vulnerable to Log4j2 CVE-2021-45105 for practicing exploitation and understanding infinite loop…

Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45046, demonstrating JNDI injection and infinite loop exploitation for educational…

Vulnerable Spring Boot web application demonstrating Log4j2 JNDI injection (CVE-2021-44228) with exploitation steps and mitigation guidance for…

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

Step-by-step TryHackMe walkthrough for exploiting the Log4Shell vulnerability (CVE-2021-44228) to achieve remote code execution and capture flags.

Sample docker-compose setup to show how this exploit works