
log4j2-rce
Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

POC for log4shll Vulnerablity (CVE-2021-44228)

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

Python3 implementation for exploiting Log4J over Jolokia

Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889

Proof-of-concept exploit for Log4j RCE (CVE-2021-4104) targeting JMS-enabled environments with modified log4j.properties. Demonstrates remote code…

Log4j Vulnerability RCE - CVE-2021-44228

Step-by-step reproduction guide for CVE-2021-44228 (Log4Shell) with JDK 8u20, vulnerable Log4j 2.14.1, marshalsec LDAP server, and custom payload…

Hands-on lab exercise for exploiting Log4Shell (CVE-2021-44228) with JNDI injection, LDAP referral servers, and reverse shell payloads. Includes…

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

Log4J Exploits for Different Systems

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating JNDI-based remote code execution via LDAP and HTTP servers.

Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including payload compilation, LDAP…

Script to create a log4j (CVE-2021-44228) exploit with support for different methods of getting a reverse shell

Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...