
log4j2-rce
Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including payload compilation, LDAP…

Script to create a log4j (CVE-2021-44228) exploit with support for different methods of getting a reverse shell

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating JNDI-based remote code execution via LDAP and HTTP servers.

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

Log4J Exploits for Different Systems

Python3 implementation for exploiting Log4J over Jolokia

This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).

Step-by-step reproduction guide for CVE-2021-44228 (Log4Shell) with JDK 8u20, vulnerable Log4j 2.14.1, marshalsec LDAP server, and custom payload…

Detailed analysis and proof-of-concept for CVE-2021-44228 (Log4j RCE), including environment setup, vulnerability analysis, JNDI injection mechanism,…

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

POC for log4shll Vulnerablity (CVE-2021-44228)

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

Hands-on lab exercise for exploiting Log4Shell (CVE-2021-44228) with JNDI injection, LDAP referral servers, and reverse shell payloads. Includes…

Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...

A Proof of Concept of the Log4j vulnerabilities (CVE-2021-44228) over Java-RMI

Log4j Vulnerability RCE - CVE-2021-44228

A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)