12/10

GitHub - YfryTchsGD/Log4jAttackSurface

https://github.com/YfryTchsGD/Log4jAttackSurface
GitHub - YfryTchsGD/Log4jAttackSurface

CVE-2021-44228 Apache Log4j RCE Attempts Dec 20th 9:27PM ET · GitHub

https://gist.github.com/gnremy/c546c7911d5f876f263309d7161a7217
CVE-2021-44228 Apache Log4j RCE Attempts Dec 20th 9:27PM ET · GitHub

Log4j RCE CVE-2021-44228 Exploitation Detection · GitHub

https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b
Log4j RCE CVE-2021-44228 Exploitation Detection · GitHub

eXploit – CVE-2021-42287/CVE-2021-42278 Weaponisation

https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html
eXploit – CVE-2021-42287/CVE-2021-42278 Weaponisation

us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf

https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf
us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf

Exploiting JNDI Injections in Java | Veracode blog

https://www.veracode.com/blog/research/exploiting-jndi-injections-java
Exploiting JNDI Injections in Java | Veracode blog

Zero-day in ubiquitous Log4j tool poses a grave threat to the Internet | Ars Technica

https://arstechnica.com/information-technology/2021/12/minecraft-and-other-apps-face-serious-threat-from-new-code-execution-bug/
Zero-day in ubiquitous Log4j tool poses a grave threat to the Internet | Ars Technica

Tweet / Twitter

https://twitter.com/GossiTheDog/status/1469121209111658498
Tweet / Twitter

エラー

https://drive.google.com/file/d/1TRx7La595vYAeojYDAX3RwBi1POL1tZc/view?usp=sharing
エラー

Canarytokens

https://canarytokens.org
Canarytokens

Query Results | GreyNoise Visualizer

https://www.greynoise.io/viz/query/?gnql=tags%3A%22Apache%20Log4j%20RCE%20Attempt%22
Query Results | GreyNoise Visualizer

Log4j zero-day gets security fix just as scans for vulnerable systems ramp up

https://therecord.media/log4j-zero-day-gets-security-fix-just-as-scans-for-vulnerable-systems-ramp-up/
Log4j zero-day gets security fix just as scans for vulnerable systems ramp up

Canarytokens

https://canarytokens.org/generate#
Canarytokens

active-scan-plus-plus/activeScan++.py at master · PortSwigger/active-scan-plus-plus · GitHub

https://github.com/PortSwigger/active-scan-plus-plus/blob/master/activeScan++.py
active-scan-plus-plus/activeScan++.py at master · PortSwigger/active-scan-plus-plus · GitHub

us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf

https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf
us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf

Log4j – Apache Log4j Security Vulnerabilities

https://logging.apache.org/log4j/2.x/security.html
Log4j – Apache Log4j Security Vulnerabilities

PentesterLab: Learn Web App Pentesting!

https://pentesterlab.com/exercises/log4j_rce/course
PentesterLab: Learn Web App Pentesting!

1.6 Million WordPress Sites Under Cyberattack From Over 16,000 IP Addresses

https://thehackernews.com/2021/12/16-million-wordpress-sites-under.html
1.6 Million WordPress Sites Under Cyberattack From Over 16,000 IP Addresses

GitHub - wyunan/Log4j-rce: Log4j-rce

https://github.com/Al0sc/Log4j-rce
GitHub - wyunan/Log4j-rce: Log4j-rce

Space / Twitter

https://twitter.com/i/spaces/1MnGnkbOXYoJO
Space / Twitter

conti-cyber-attack-on-the-hse-full-report.pdf

https://www.hse.ie/eng/services/publications/conti-cyber-attack-on-the-hse-full-report.pdf
conti-cyber-attack-on-the-hse-full-report.pdf

Proofpoint Emerging Threats Rules

https://rules.emergingthreatspro.com/open/
Proofpoint Emerging Threats Rules

New zero-day exploit for Log4j Java library is an enterprise nightmare

https://www.bleepingcomputer.com/news/security/new-zero-day-exploit-for-log4j-java-library-is-an-enterprise-nightmare/
New zero-day exploit for Log4j Java library is an enterprise nightmare

Log4Shell: Nuevo 0-day Y Exploit RCE En Apache Log4j (CVE-2021-44228) | CronUp Ciberseguridad

https://www.cronup.com/log4shell-nuevo-0-day-y-exploit-rce-en-apache-log4j-cve-2021-44228/
Log4Shell: Nuevo 0-day Y Exploit RCE En Apache Log4j (CVE-2021-44228) | CronUp Ciberseguridad

BlackCat: A New Rust-based Ransomware Malware Spotted in the Wild

https://thehackernews.com/2021/12/blackcat-new-rust-based-ransomware.html
BlackCat: A New Rust-based Ransomware Malware Spotted in the Wild

GitHub - nice0e3/log4j_POC

https://github.com/nice0e3/log4j_POC
GitHub - nice0e3/log4j_POC

Python setter for property sAMAccountName for CVE-2021-42287/CVE-2021-42278 · GitHub

https://gist.github.com/snovvcrash/3bf1a771ea6b376d374facffa9e43383
Python setter for property sAMAccountName for CVE-2021-42287/CVE-2021-42278 · GitHub

Russia Blocks Tor Privacy Service in Latest Censorship Move

https://thehackernews.com/2021/12/russia-blocks-tor-privacy-service-in.html
Russia Blocks Tor Privacy Service in Latest Censorship Move

Massive attack against 1.6 million WordPress sites underway

https://www.bleepingcomputer.com/news/security/massive-attack-against-16-million-wordpress-sites-underway/
Massive attack against 1.6 million WordPress sites underway

Enterprise Attack Initial Access w/ Steve Borosh - Antisyphon

https://www.antisyphontraining.com/enterprise-attack-initial-access-w-steve-borosh/#course-scheduleY
Enterprise Attack Initial Access w/ Steve Borosh - Antisyphon

Tweet / Twitter

https://twitter.com/GossiTheDog/status/1469248250670727169
Tweet / Twitter

A Simple Exploit is Exposing the Biggest Apps on the Internet

https://www.vice.com/en/article/93bag7/a-simple-exploit-is-exposing-the-biggest-apps-on-the-internet
A Simple Exploit is Exposing the Biggest Apps on the Internet

Tweet / Twitter

https://twitter.com/P0rZ9/status/1468949890571337731
Tweet / Twitter

Release log4j-2.15.0-rc1 · apache/logging-log4j2 · GitHub

https://github.com/apache/logging-log4j2/releases/tag/log4j-2.15.0-rc1
Release log4j-2.15.0-rc1 · apache/logging-log4j2 · GitHub

Technical Advisory – SonicWall SMA 100 Series – Heap-Based Buffer Overflow (CVE-2021-20043) | NCC Group Research Blog | Making the world safer and more secure

https://research.nccgroup.com/2021/12/09/technical-advisory-sonicwall-sma-100-series-heap-based-buffer-overflow-cve-2021-20043/
Technical Advisory – SonicWall SMA 100 Series – Heap-Based Buffer Overflow (CVE-2021-20043) | NCC Group Research Blog | Making the world safer and more secure

2021 Internet Hall of Fame Induction Ceremony on Livestream

https://livestream.com/internetsociety/ihof2021
2021 Internet Hall of Fame Induction Ceremony on Livestream

sAMAccountName spoofing - The Hacker Recipes

https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing
sAMAccountName spoofing - The Hacker Recipes

Technical Advisory – SonicWall SMA 100 Series – Unauthenticated File Upload Path Traversal (CVE-2021-20040) | NCC Group Research Blog | Making the world safer and more secure

https://research.nccgroup.com/2021/12/09/technical-advisory-sonicwall-sma-100-series-unauthenticated-file-upload-path-traversal-cve-2021-20040/
Technical Advisory – SonicWall SMA 100 Series – Unauthenticated File Upload Path Traversal (CVE-2021-20040) | NCC Group Research Blog | Making the world safer and more secure

Log4j RCE 0-day actively exploited | CERT NZ

https://www.cert.govt.nz/it-specialists/advisories/log4j-rce-0-day-actively-exploited/
Log4j RCE 0-day actively exploited | CERT NZ

Worst Apache Log4j RCE Zero day Dropped on Internet - Cyber Kendra

https://www.cyberkendra.com/2021/12/worst-log4j-rce-zeroday-dropped-on.html
Worst Apache Log4j RCE Zero day Dropped on Internet - Cyber Kendra