
log4j2-rce
Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

CVE-2017-5645 - Apache Log4j RCE due Insecure Deserialization

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

Step-by-step reproduction guide for CVE-2021-44228 (Log4Shell) with JDK 8u20, vulnerable Log4j 2.14.1, marshalsec LDAP server, and custom payload…

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection payloads, WAF bypass techniques, and passive scanning integration for…

Hands-on lab exercise for exploiting Log4Shell (CVE-2021-44228) with JNDI injection, LDAP referral servers, and reverse shell payloads. Includes…

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

Log4J CVE-2021-44228 Minecraft PoC

Python3 implementation for exploiting Log4J over Jolokia

Script to create a log4j (CVE-2021-44228) exploit with support for different methods of getting a reverse shell

Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...

Log4J Exploits for Different Systems

Detailed analysis and proof-of-concept for CVE-2021-44228 (Log4j RCE), including environment setup, vulnerability analysis, JNDI injection mechanism,…

A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)