Some of our researchers recently published a proof-of-concept for an important vulnerability in a widely used java library.
Please make sure all of your java applications that are using #Log4j2 (including Elasticsearch or Minecraft servers) are patched up!! #log4jRCE#Log4Shell
@k0zmer @z9frme and myself made a proof-of-concept (POC) exploit for the recently released log4shell vulnerability (CVE-2021-44228).
We also made a vulnerable application to test payloads on and play with. All of this can be found on the following repo:
https://t.co/CHpKfLhGck
Working on a source code analytic tool, agnostic of language, called codeCTRL for pwnCTRL. The source code is fully open source and is available at https://t.co/rW4dlYX6FK. If you're interested in participating in the development, please feel free to crea…https://t.co/iwY9ZqoX2o