12/11

Tweet / Twitter

https://twitter.com/theasf/status/1400875147163279374
Tweet / Twitter

Canarytokens

https://canarytokens.org
Canarytokens

Log4j RCE CVE-2021-44228 Exploitation Detection · GitHub

https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b
Log4j RCE CVE-2021-44228 Exploitation Detection · GitHub

Releases · NationalSecurityAgency/ghidra · GitHub

https://github.com/NationalSecurityAgency/ghidra/releases
Releases · NationalSecurityAgency/ghidra · GitHub

BlueTeam CheatSheet * Log4Shell* | Last updated: 2021-12-20 2238 UTC · GitHub

https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592
BlueTeam CheatSheet * Log4Shell* | Last updated: 2021-12-20 2238 UTC · GitHub

us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf

https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf
us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf

GreyNoise Log4Shell Payloads · GitHub

https://gist.github.com/nathanqthai/01808c569903f41a52e7e7b575caa890
GreyNoise Log4Shell Payloads · GitHub

Incredible RCE (Struts2 ft Log4j2) - YouTube

https://www.youtube.com/watch?v=D-TwQRoX6Fk
Incredible RCE (Struts2 ft Log4j2) - YouTube

Log4j – Apache Log4j Security Vulnerabilities

https://logging.apache.org/log4j/2.x/security.html
Log4j – Apache Log4j Security Vulnerabilities

Canarytokens

https://canarytokens.org/generate#
Canarytokens

Extremely Critical Log4J Vulnerability Leaves Much of the Internet at Risk

https://thehackernews.com/2021/12/extremely-critical-log4j-vulnerability.html
Extremely Critical Log4J Vulnerability Leaves Much of the Internet at Risk

GitHub - YfryTchsGD/Log4jAttackSurface

https://github.com/YfryTchsGD/Log4jAttackSurface
GitHub - YfryTchsGD/Log4jAttackSurface

sAMAccountName spoofing - The Hacker Recipes

https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing
sAMAccountName spoofing - The Hacker Recipes

Statement from CISA Director Easterly on “Log4j” Vulnerability | CISA

https://www.cisa.gov/news/2021/12/11/statement-cisa-director-easterly-log4j-vulnerability
Statement from CISA Director Easterly on “Log4j” Vulnerability | CISA

active-scan-plus-plus/activeScan++.py at master · PortSwigger/active-scan-plus-plus · GitHub

https://github.com/PortSwigger/active-scan-plus-plus/blob/master/activeScan++.py
active-scan-plus-plus/activeScan++.py at master · PortSwigger/active-scan-plus-plus · GitHub

Apache Logging Services

http://logging.apache.org/
Apache Logging Services

The Week in Ransomware - December 10th 2021 - Project CODA

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-december-10th-2021-project-coda/
The Week in Ransomware - December 10th 2021 - Project CODA

CVE-2021-44228 Apache Log4j RCE Attempts Dec 20th 9:27PM ET · GitHub

https://gist.github.com/gnremy/c546c7911d5f876f263309d7161a7217
CVE-2021-44228 Apache Log4j RCE Attempts Dec 20th 9:27PM ET · GitHub

VMSA-2021-0028.13

https://www.vmware.com/security/advisories/VMSA-2021-0028.html
VMSA-2021-0028.13