Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

DHS warns of critical flaw in widely used software [Log4j]
CNN ^ | December 11, 2021 | Sean Lyngaas,

Posted on 12/12/2021 6:20:07 PM PST by BenLurkin

The vulnerability is in Java-based software known as "Log4j" that large organizations, including some of the world's biggest tech firms, use to configure their applications.

Apple's cloud computing service, security firm Cloudflare and one of the world's most popular video games, Minecraft, are among the organizations that run Log4j, according to security researchers.

The vulnerability can offer a hacker a relatively easy way to access an organization's computer server. From there, an attacker could devise other ways to access systems on an organization's network.

Security experts say that the fallout from the software flaw could continue for days and weeks as organizations race to address the issue.

The situation escalated before the weekend when a tool for exploiting the vulnerability was made public on GitHub, a software repository. That gave malicious hackers a potential roadmap for how to use the vulnerability to break into devices.

Easterly said her agency would hold a call with critical infrastructure firms across the country on Monday to brief them on the situation.

(Excerpt) Read more at cnn.com ...


TOPICS: Computers/Internet
KEYWORDS: apple; clintonnonnews; cloudflare; cnn; dhs; github; hacking; java; log4j; mediawingofthednc; minecraft; panicporn; partisanmediashill; partisanmediashills; seanlyngaas; zeroday

1 posted on 12/12/2021 6:20:07 PM PST by BenLurkin
[ Post Reply | Private Reply | View Replies]

To: BenLurkin

Yup - woke up to find out our Bangalore team devops had spent their Sunday working to identify components using log4j and update to 2.15.0.


2 posted on 12/12/2021 6:31:24 PM PST by AnotherUnixGeek
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

This even affects Ingenuity, the Mars helicopter.


3 posted on 12/12/2021 6:55:31 PM PST by TChad ("Joe, we should evacuate the civilians before the military. You understand that, right? Joe?")
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Its fairly simple to update the log4j library to the latest version and I bet a lot of IT people are spending their weekend doing just that.

The vulnerablity is related to the log4j JndiLookup class that is responsible for string substitutions in the log message. I suspect the hackers can load a bogus hacked file to the server and then replace the intended string substitution with malware code of their choosing from the hacked file.

Disabling the log4j2.formatMsgNoLookups system property, or setting the LOG4J_FORMAT_MSG_NO_LOOKUPS environment variable to true will block this vulnerability until the new library can be installed.


4 posted on 12/12/2021 7:35:03 PM PST by Dave Wright
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin
I call shenanigans on this, the claims that are being made do not match up with the corresponding CVE, which requires other internally compromised services to work, such as LDAP.

Methinks this vulnerability as seen in the wild is due to vulnerable Active Directory installations when the CVE is updated and scored.

5 posted on 12/12/2021 7:44:17 PM PST by SecondAmendment (This just proves my latest theory ... LEFTISTS RUIN EVERYTHING !!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin; ShadowAce; Swordmaker

Not that there isn’t an IT/Sec/Sysadmin anywhere that isn’t already aware of this, but what the heck, *ping* anyway....


6 posted on 12/12/2021 9:06:03 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Heh, we have a lot of software made with that.

Glad I’m not coding. Too many people do not revisit their code and can’t do an upgrade, easily. Heck, even identifying all the software in production using it will take weeks.


7 posted on 12/12/2021 9:32:09 PM PST by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ConservativeMind
I'll be updating my Maven pom.xml and Gradle build.gradle files in the morning. Log4j is a staple in Java code running in web servers. Lots of rebuild/redeploy coming ASAP.
8 posted on 12/12/2021 9:50:26 PM PST by Myrddin
[ Post Reply | Private Reply | To 7 | View Replies]

To: BenLurkin; rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; ...

9 posted on 12/13/2021 3:48:01 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson