
취약한 LOG4J 버전용 해시
취약한 LOG4J 버전용 해시
조직이 취약한 버전을 검색하는 데 도움이 되도록 만들어졌습니다
https://www.lunasec.io/docs/blog/log4j-zero-day/
해시 출처: https://archive.apache.org/dist/logging/log4j/
1.X도 영향을 받을 가능성이 있음: https://github.com/apache/logging-log4j2/pull/608
버전 1.0은 취약하지 않음: https://twitter.com/ceki/status/1469449618316533762?s=20
탐지 규칙: https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b
VMware 취약 제품: https://www.randori.com/blog/cve-2021-44228/
개념 증명(PoC) JNDI/LDAP 서버: https://github.com/veracode-research/rogue-jndi