ãã¾ãã¾ãªããã¸ã§ã¯ãã§åºã使ããã¦ããJava製ã®ãã°åºåã©ã¤ãã©ãªãApache Log4jãã«ãªã¢ã¼ãã³ã¼ãå®è¡ï¼RCEï¼ã®èå¼±æ§ãåå¨ãããã¨ãæããã«ãªããæ³¢ç´ãåºãã£ã¦ãã¾ãã
マイクラもハッキング ~「Apache Log4j」ライブラリに致命的なリモートコード実行のゼロデイ脆弱性【12月10日18:45追記】 - やじうまの杜 - 窓の杜
ããLog4jãã¯å¹ åºãç¨ãããã¦ãããããä»ã¾ã§ã«æããã½ããããã¬ã¼ã ã¯ã¼ã¯ããµã¼ãã¹ã®ã»ãã«ãå½±é¿ãããã®ã¯ããªãå¤ããã§ãï¼ãSteamãããApple iCloudããå½±é¿ãåããã¨ã®æ å ±ãï¼ããã§ã«å¯¾ççï¼v2.15.0ï¼ã¯ãã§ã«ãªãªã¼ã¹ããã¦ãããããªã®ã§ãä¸å»ãæ©ã対çãæã¾ãã¾ãã
マイクラもハッキング ~「Apache Log4j」ライブラリに致命的なリモートコード実行のゼロデイ脆弱性【12月10日18:45追記】 - やじうまの杜 - 窓の杜
ä»ååé¡ã¨ãªã£ã¦ããã®ã¯Jndi Lookupã ãããã¯Javaã®Java Naming and Directory Interfaceã«ããå¤æ°åã®ç½®æã§ããããã¯ã¼ã¯è¶ãã«å¤æ°ã«ç¸å½ããå¤ãæ¤ç´¢ãããã¨ãã§ããããã®ä¸ã«LDAPãå«ã¾ãããä¾ãã°"${jndi:ldap://someremoteclass}"ã®ããã«ãªãã
log4jの脆弱性について
äºæ¬æ¾ãããã
2.15.0ã«ã¢ããã°ã¬ã¼ãã§ããªãã¦ã¼ã¶ã¼ã¯ã以ä¸ã®æ¹æ³ã§æ´é²ã軽æ¸ãããã¨ãã§ãã¾ãã
ã»>Log4j 2.10以ä¸ã®ã¦ã¼ã¶ã¼ã¯ããã°ã»ã¤ãã³ãã»ã¡ãã»ã¼ã¸ã®ã«ãã¯ã¢ãããé²ãããã«ãã³ãã³ãã©ã¤ã³ã»ãªãã·ã§ã³ã¨ãã¦-Dlog4j.fatormatMsgNoLookups=trueã追å ããããã¯ã©ã¹ãã¹ä¸ã®log4j2.component.propertiesãã¡ã¤ã«ã«log4j.fatormatMsgNoLookups=trueã追å ãããã¨ãã§ãã¾ãã
ã»>Log4j 2.7 以éã®ã¦ã¼ã¶ã¯ããã°ã»ã¤ãã³ãã»ã¡ãã»ã¼ã¸å ã®ã«ãã¯ã¢ãããé²æ¢ããããã« PatternLayout æ§æ㧠%m{nolookups} ãæå®ã§ãã¾ãã
ã»>log4j-core jar ãã JndiLookup ã¯ã©ã¹ã¨ JndiManager ã¯ã©ã¹ãåé¤ãã¾ãããJndiManager ãåé¤ããã¨ãJndiContextSelector 㨠JMSAppender ãæ©è½ããªããªãã¾ãã
é¢é£URL
- log4jã®èå¼±æ§ã«ã¤ãã¦
- GitHub - apache/logging-log4j2: Apache Log4j 2 is an upgrade to Log4j that provides significant improvements over its predecessor, Log4j 1.x, and provides many of the improvements available in Logback while fixing some inherent problems in Logback's architecture.
- Log4j RCE Found | Hacker News
- GitHub - YfryTchsGD/Log4jAttackSurface
- Log4j 2.14.1ã®èå¼±æ§å¯¾å¿
- us-16-MunozMirosh-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE
- ããã°ãããããJavaã©ã¤ãã©ãªãLog4jãã«ã¼ããã¤èå¼±æ§ãä»»æã®ãªã¢ã¼ãã³ã¼ããå®è¡å¯è½ãiCloudãSteamãMinecraftãªã©åºç¯å²ã®Java製åã«å½±é¿ã - ITmedia NEWS
- ãã¤ã¯ã©ããããã³ã° ï½ãApache Log4jãã©ã¤ãã©ãªã«è´å½çãªãªã¢ã¼ãã³ã¼ãå®è¡ã®ã¼ããã¤èå¼±æ§ã12æ10æ¥18:45追è¨ã - ãããã¾ã®æ - çªã®æ
- log4j2èå¼±æ§ï¼ãã¤ã¯ã©å ¨ãµã¼ãã¼(ããã©ãSpigotãPaperãªã©) | 令åã®ç¥æµè¢
- Restrict LDAP access via JNDI by rgoers · Pull Request #608 · apache/logging-log4j2 · GitHub
- ä»ååé¡ã¨ãªã£ã¦ããã®ã¯Jndi Lookupã ãããã¯Javaã®Java Naming and Directory Interfaceã«ããå¤æ°åã®ç½®æã§ããããã¯ã¼ã¯è¶ãã«å¤æ°ã«ç¸å½ããå¤ãæ¤ç´¢ãããã¨ãã§ããããã®ä¸ã«LDAPãå«ã¾ãããä¾ãã°"${jndi:ldap://someremoteclass}"ã®ããã«ãªãã
- Log4J2ã®ãã¼ã¸ã§ã³ã¢ããã®ãããã - æ¥ã 常ã
- CVE-2021-44228 - Log4j RCE 0-day mitigation
- Exploiting JNDI Injections in Java | Veracode blog
- Apache Releases Log4j Version 2.15.0 to Address Critical RCE Vulnerability Under Exploitation | CISA
- CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints