Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
log4j-cve-2021-44228 — Ansible 플레이북으로 Red Hat의 Log4j 탐지 스크립트를 자동화하여 GPG 검증과 함께 CVE-2021-44228(Log4Shell) 취약점을 Linux 호스트에서 스캔합니다. | Kitploit
도구/GitHubGitHub/lucab85/log4j-cve-2021-44228
Vulnerability ScannersVulnerability AnalysisScripting & AutomationConfiguration AuditingCloud SecurityDevSecOps
GitHublucab85/log4j-cve-2021-44228

log4j-cve-2021-44228

Ansible 플레이북으로 Red Hat의 Log4j 탐지 스크립트를 자동화하여 GPG 검증과 함께 CVE-2021-44228(Log4Shell) 취약점을 Linux 호스트에서 스캔합니다.

저장소 보기
5710114년 전Kitploit 검토 완료
웹사이트

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Log4j-CVE-2021-44228 탐지 스캐너 플레이북

CI

Log4Shell(CVE-2021-44228)용 공식 Red Hat Log4j 탐지 스크립트를 사용하여 대상 Linux 호스트를 검증하는 Ansible 플레이북입니다.

Red Hat 버전 1.3 탐지기 2022-01-10.

결과는 detector_dir 아래의 txt 파일에 저장됩니다 (기본값: /opt/cve-2021-44228/).

Ansible Galaxy 역할

코드는 또한 Ansible Galaxy 역할 lucab85.ansible_role_log4shell로 제공됩니다.```bash ansible-galaxy install lucab85.ansible_role_log4shell

## Ansible Playbook 실행 방법

기본 변수는 영향을 받는 파일을 찾기 위해 `/var/` 경로 전체를 스캔합니다.
더 많은 옵션을 위해 `vars.yml` 파일을 사용자 지정할 수 있습니다.```bash
ansible-playbook log4j-cve-2021-44228.yml

의존성

없음.

요구 사항

ansible 2.9+

변수 vars.yml

기본값:```yaml rh_bullettin: >- https://access.redhat.com/security/vulnerabilities/RHSB-2021-009 intro: | Ansible Playbook tested with detector version 1.3 released 2022-01-10. If a 404 error occur please adjust the URL with the latest version available for detector URL. Please refer to the Red Hat Security Bullettin for up-to-date information and adjust the playbook variables accordingly. {{ rh_bullettin }}. vulnerable: | System MIGHT be vulnerable to log4j (CVE-2021-44228) not_vulnerable: | System IS NOT vulnerable to log4j (CVE-2021-44228) report_txt: "/report/vuln_log4j2_path_*.txt" sh_detector: "cve-2021-44228--2022-01-10-1242.sh" sh_signature: "cve-2021-44228--2022-01-10-1242.sh.asc" detector_baseurl: "https://access.redhat.com/sites/default/files/" force_download: false detector_path: "/var/" detector_dir: "/opt/cve-2021-44228/" detector_run_dir: "tmp" detector_options: '-n -d --no-progress --scan {{ detector_path }}' gpg_keyid: "7514F77D8366B0D9" gpg_server: "pgp.mit.edu" gpg_public_key: 'gpg --keyserver {{ gpg_server }} --recv {{ gpg_keyid }}' clean_run_before: true delete_after: false verify_gpg: true

- `rh_bullettin`: RHSB 링크 (기본값: [https://access.redhat.com/security/vulnerabilities/RHSB-2021-009](https://access.redhat.com/security/vulnerabilities/RHSB-2021-009))
- `intro`: 소개 텍스트
- `vulnerable`: 취약한 텍스트 (디버그 레벨 2 실행 `-vv`에서만 표시)
- `not_vulnerable`: 취약하지 않음 텍스트 (디버그 레벨 2 실행 `-vv`에서만 표시)
- `report_txt`: 출력할 리포트 경로 (기본값: `/report/vuln_log4j2_path_*.txt`)
- `sh_detector`: 탐지기 bash 스크립트 파일의 파일명
- `sh_signature`: 탐지기 GPG 서명 파일의 파일명
- `detector_baseurl`: 이전 파일들을 다운로드할 기본 URL
- `force_download`: 실행할 때마다 코드를 강제로 다운로드 (기본값: `false`)
- `detector_path`: 검사할 경로 (기본값: `/var/`)
- `detector_dir`: 탐지기 다운로드 경로 (기본값: `/opt/cve-2021-44228/`)
- `detector_run_dir`: 실행 전에 생성할 하위 디렉터리 (기본값: `tmp`)
- `detector_options`: 탐지기 스크립트용 명령줄 옵션 (기본값: `-n -d --no-progress --scan {{ detector_path }}`)
- `gpg_keyid`: 검증을 위해 다운로드할 GPG 공개 키 (기본값: Red Hat Product Security `7514F77D8366B0D9`)
- `gpg_server`: GPG 키 서버 (기본값: `pgp.mit.edu`)
- `gpg_public_key`: gpg 검증 명령 (기본값: `gpg --keyserver {{ gpg_server }} --recv {{ gpg_keyid }}`)
- `clean_run_before`: 실행 전에 실행 디렉터리를 제거하고 다시 생성 - 탐지기는 빈 디렉터리가 필요합니다 (기본값: `true`)
- `delete_after`: 실행 후 _detector_dir_ 제거 (기본값: `false`)
- `verify_gpg`: GPG 서명 다운로드 및 검증 수행 (기본값: `true`)

## 데모 실행

RHEL8 데모 대상 호스트에 대한 플레이북 실행의 전체 출력:```bash
$ ansible-playbook -i test/inventory log4j-cve-2021-44228.yml -vv
ansible-playbook [core 2.12.1]
  config file = None
  configured module search path = ['/Users/lberton/.ansible/plugins/modules', '/usr/share/ansible/plugins/modules']
  ansible python module location = /usr/local/Cellar/ansible/5.1.0/libexec/lib/python3.10/site-packages/ansible
  ansible collection location = /Users/lberton/.ansible/collections:/usr/share/ansible/collections
  executable location = /usr/local/bin/ansible-playbook
  python version = 3.10.1 (main, Dec  6 2021, 23:20:29) [Clang 13.0.0 (clang-1300.0.29.3)]
  jinja version = 3.0.3
  libyaml = True
No config file found; using defaults
Skipping callback 'default', as we already have a stdout callback.
Skipping callback 'minimal', as we already have a stdout callback.
Skipping callback 'oneline', as we already have a stdout callback.

PLAYBOOK: log4j-cve-2021-44228.yml *********************************************************************************************************************************************************
2 plays in log4j-cve-2021-44228.yml

PLAY [download detector for Apache Log4j (CVE-2021-44228)] *********************************************************************************************************************************
META: ran handlers

TASK [include_vars] ************************************************************************************************************************************************************************
task path: /Users/lberton/prj/github/log4j-cve-2021-44228/log4j-cve-2021-44228.yml:29
ok: [localhost] => {"ansible_facts": {"clean_run_before": true, "delete_after": false, "detector_baseurl": "https://access.redhat.com/sites/default/files/", "detector_dir": "/opt/cve-2021-44228/", "detector_options": "-n -d --no-progress --scan {{ detector_path }}", "detector_path": "/var/", "detector_run_dir": "tmp", "force_download": false, "gpg_keyid": "7514F77D8366B0D9", "gpg_public_key": "gpg --keyserver {{ gpg_server }} --recv {{ gpg_keyid }}", "gpg_server": "pgp.mit.edu", "intro": "Ansible Playbook tested with detector version 1.3 released 2022-01-10.\nIf a 404 error occur please adjust the URL with the latest version available\nfor detector URL.\nPlease refer to the Red Hat Security Bullettin for up-to-date information and\nadjust the playbook variables accordingly.\n{{ rh_bullettin }}.\n", "not_vulnerable": "System IS NOT vulnerable to log4j (CVE-2021-44228)\n", "report_txt": "/report/vuln_log4j2_path_*.txt", "rh_bullettin": "https://access.redhat.com/security/vulnerabilities/RHSB-2021-009", "sh_detector": "cve-2021-44228--2022-01-10-1242.sh", "sh_signature": "cve-2021-44228--2022-01-10-1242.sh.asc", "verify_gpg": true, "vulnerable": "System MIGHT be vulnerable to log4j (CVE-2021-44228)\n"}, "ansible_included_var_files": ["/Users/lberton/prj/github/log4j-cve-2021-44228/vars.yml"], "changed": false}

TASK [print information] *******************************************************************************************************************************************************************
task path: /Users/lberton/prj/github/log4j-cve-2021-44228/log4j-cve-2021-44228.yml:31
ok: [localhost] => {
    "msg": "Ansible Playbook tested with detector version 1.3 released 2022-01-10.\nIf a 404 error occur please adjust the URL with the latest version available\nfor detector URL.\nPlease refer to the Red Hat Security Bullettin for up-to-date information and\nadjust the playbook variables accordingly.\nhttps://access.redhat.com/security/vulnerabilities/RHSB-2021-009.\n"
}

TASK [download detector] *******************************************************************************************************************************************************************
task path: /Users/lberton/prj/github/log4j-cve-2021-44228/log4j-cve-2021-44228.yml:35
ok: [localhost] => {"changed": false, "dest": "./cve-2021-44228--2022-01-10-1242.sh", "elapsed": 0, "gid": 20, "group": "staff", "mode": "0644", "msg": "HTTP Error 304: Not Modified", "owner": "lberton", "size": 67710, "state": "file", "status_code": 304, "uid": 501, "url": "https://access.redhat.com/sites/default/files/cve-2021-44228--2022-01-10-1242.sh"}
도구 다운로드