filmov
tv
Fuzzing Java to Find Log4j Vulnerability - CVE-2021-45046
![preview_player](https://i.ytimg.com/vi/kvREvOvSWt4/maxresdefault.jpg)
Показать описание
After the log4shell (CVE-2021-44228) vulnerability was patched with version 2.15, another CVE was filed. Apparently log4j was still vulnerable in some cases to a denial of service. However it turned out that on some systems, the issue can still lead to a remote code execution. In this video we use the Java fuzzer Jazzer to find a bypass.
00:00 - Intro
00:54 - Chapter #1: The New CVE
03:38 - Chapter #2: Disable Lookups
05:43 - Chapter #3: Vulnerable log4j Configs
07:52 - Chapter #4: The Remote Code Execution
10:53 - Chapter #5: Parser Differential
12:57 - Chapter #6: Differential Fuzzing
16:07 - Chapter #7: macOS Only
18:15 - Chapter #8: Increase Impact
19:03 - Summary
19:58 - Outro
-=[ ❤️ Support ]=-
-=[ 🐕 Social ]=-
00:00 - Intro
00:54 - Chapter #1: The New CVE
03:38 - Chapter #2: Disable Lookups
05:43 - Chapter #3: Vulnerable log4j Configs
07:52 - Chapter #4: The Remote Code Execution
10:53 - Chapter #5: Parser Differential
12:57 - Chapter #6: Differential Fuzzing
16:07 - Chapter #7: macOS Only
18:15 - Chapter #8: Increase Impact
19:03 - Summary
19:58 - Outro
-=[ ❤️ Support ]=-
-=[ 🐕 Social ]=-
Fuzzing Java to Find Log4j Vulnerability - CVE-2021-45046
Can we find Log4Shell with Java Fuzzing? 🔥 (CVE-2021-44228 - Log4j RCE)
Automated Fuzzing | How You Can Find the Log4j Vulnerability in Less Than 10 Minutes
Fuzzing Java code (JSoup) using Jazzer fuzzer - Java Security
Automatically detecting log4j vulnerabilities in your IT | #CMKduo Episode 1
What is Log4Shell (Log4J RCE) and why does it matter?
How To Find Log4j vulnerability on multiple Urls 2022 | Live Testing by #Hacktube #log4j
Another Log4j Vulnerability and The CIS Response Playbook
Log4j
Log4J - CVE 2021-44228 (Log4Shell) - Exploitation & Mitigation
How to find which devices are affected by Log4j with Cybellum
Log4j Lookups in Depth // Log4Shell CVE-2021-44228 - Part 2
Solar, exploiting log4j from 'Tryhackme'
TryHackMe - 'Solar' Leveraging Log4j Exploit and Mitigation
Writing A Java Security Test in Less Than A Minute
Learn How to Fuzz Your Rust Code in 10 Minutes
Santa brought us a 0-day?! Unauthenticated RCE in critical Java logging utility Log4j
Log4J vulnerability | Live Demonstration & Lab Configuration | Practical - Part 1
*Bonus* Log4J: What You Need to Know and How To Respond
2022 - Introduction to modern fuzzing
Create a log4j App and Hack It | CVE-2021-44228
Apache Struts2 Log4j RCE | 0day | CVE-2021-44228 | POC | Log4shell | log4j vulnerability
Finding Buffer Overflow with Fuzzing | Ep. 04
Going Beyond Unit Testing | How to Uncover Blind Spots in your Java Code with Fuzzing
Комментарии