Hello Folks ๐
Finally, the long wait has come to an end!โจ
We are Glad to Present the Announcement Stream of *Development Days of December* ๐จโ๐ป๐คฉ
We got lots of surprises tomorrow ๐( Probably Gonna be your secret Santa ? ๐ )
How do I know if Log4j is vulnerable?
Check if any information logged with Log4J includes information like URLs, headers, or cookies, that the user can manipulate.
If one of these is being logged, the project is vulnerable.
Log4j
Java-based logging frameworks
An open source software that is widely used by businesses and web portals.
Developer(s): Apache Software Foundation
How is Log4j being exploited?
By sending specially crafted messages to a system that uses Log4j, a threat actor can cause the system to load external code, an action known as remote command execution.
Public:
Allow companies to publicly expose information and functionalities of one or more applications to third parties
Advantages:
Delegated R&D
Increased reach, traffic
New revenue stream
Partner:
Used to facilitate communication and integration of software between a company and its business partners.
Advantages:
Up sell
Value-added service
Must have for business partners