Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Internet is scrambling to fix Log4Shell, the worst hack in history
BGR via msn ^ | 12 December 2021 | Chris Smith

Posted on 12/12/2021 9:08:33 PM PST by blueplum

Massive data breaches have become so common that we’ve gotten numb to reports detailing another hack or 0-day exploit. That doesn’t reduce the risk of such events happening, as the cat-and-mouse game between security experts and hackers continues. As some vulnerabilities get fixed, others pop up requiring attention from product and service providers. The newest one has a name that will not mean anything to most people. They call the hack Log4Shell in security briefings, which doesn’t sound very scary. But the new 0-day attack is so significant that some people see it as the worst internet hack in history....

...Patching the vulnerability is possible, and companies have started deploying fixes. But each separate internet entity will have to handle the matter on its own servers and systems. ...

...Meyers is the senior vice president of intelligence at Crowdstrick, a cybersecurity company monitoring the Log4Shell hack. He revealed that hackers “fully weaponized” the vulnerability just 12 hours after researchers initially disclosed it....

(Excerpt) Read more at msn.com ...


TOPICS: Business/Economy; Crime/Corruption; News/Current Events
KEYWORDS: apple; cloudcomputing; cloudflare; computers; crowdstrick; dhs; github; hacking; internet; internetsecurity; it; java; log4j; log4shell; logservices; minecraft; zeroday
Navigation: use the links below to view more comments.
first 1-2021-31 next last

1 posted on 12/12/2021 9:08:34 PM PST by blueplum
[ Post Reply | Private Reply | View Replies]

To: blueplum

The direct link to BGR:

https://bgr.com/tech/internet-is-scrambling-to-fix-log4shell-the-worst-hack-in-history/

MSN did not author this article.


2 posted on 12/12/2021 9:11:47 PM PST by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: blueplum

What idiot thought it would be a good idea to have RCE capability in a logging utility?


3 posted on 12/12/2021 9:18:25 PM PST by vikingd00d (chown -R us ~you/base)
[ Post Reply | Private Reply | To 1 | View Replies]

To: vikingd00d

It’s not normally there.

This is a vulnerability that makes that happen to the OS.


4 posted on 12/12/2021 9:26:16 PM PST by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: ShadowAce

tech-ping


5 posted on 12/12/2021 9:31:26 PM PST by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: vikingd00d

I’ve always hated JAVA.


6 posted on 12/12/2021 9:32:22 PM PST by Bikkuri (I am proud to be a PureBlood.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: ConservativeMind

>>It’s not normally there.

Wrong. That “feature” was deliberately coded.

From a different article on it:

The bug, now officially denoted CVE-2021-44228, involves sending a request to a vulnerable server in which you include some data – for example, an HTTP header – that you expect (or know) the server will write to its logfile.

But you booby-trap that data so that the server, while wrangling the data into a format suitable for logging, kicks off a web download as an integral part of constructing the needed log entry.

And not just any old download: if the data that comes back is a valid Java program (a .class file, in the jargon), then the server runs that file to “help” it generate the logging data.

The trick is that, by default, unpatched versions of the Log4j library permit logging requests to trigger general-purpose LDAP (directory services) searches, as well as various other online lookups.


7 posted on 12/12/2021 9:34:28 PM PST by vikingd00d (chown -R us ~you/base)
[ Post Reply | Private Reply | To 4 | View Replies]

To: vikingd00d
“The trick is that, by default, unpatched versions of the Log4j library permit logging requests to trigger general-purpose LDAP (directory services) searches, as well as various other online lookups.”

You just proved it's not performing remote code execution. There's nothing in Log4j that lets you run any code. It does a lookup, but that is not executed code or arbitrary code.

8 posted on 12/12/2021 9:39:11 PM PST by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ConservativeMind

>>There’s nothing in Log4j that lets you run any code.

Did you miss THIS?

“And not just any old download: if the data that comes back is a valid Java program (a .class file, in the jargon), then the server runs that file to “help” it generate the logging data.”

Downloading and running arbitrary code seems like a bad idea.


9 posted on 12/12/2021 9:44:43 PM PST by vikingd00d (chown -R us ~you/base)
[ Post Reply | Private Reply | To 8 | View Replies]

To: vikingd00d

Again, log4j does not ever run such code. It does now, only under an exploit.


10 posted on 12/12/2021 9:50:15 PM PST by ConservativeMind (Trump: Befuddling Democrats, Republicans, and the Media for the benefit of the US and all mankind.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: ConservativeMind

Ummmmm... that’s what the entire panic is over. A security flaw means that Log4J will retrieve client-supplied URLs including executing Java code. That’s not good.


11 posted on 12/12/2021 11:04:53 PM PST by TennesseeProfessor
[ Post Reply | Private Reply | To 10 | View Replies]

To: blueplum
the anethesiologist I sent a few thousand dollars out of pocket to (for about an hours work) just sent a letter informing me that they had a data breach so I should watch out for identity theft

its a wonderful world

https://www.reuters.com/markets/euro...L6cKZXUrr6prI0

12 posted on 12/12/2021 11:22:07 PM PST by KTM rider (The COVID 19 scam is simply TERRORISM )
[ Post Reply | Private Reply | To 1 | View Replies]

To: TennesseeProfessor
could this be related ?

https://www.reuters.com/markets/europe/exclusive-imf-10-countries-simulate-cyber-attack-global-financial-system-2021-12-09/?fbclid=IwAR3fiRQ05BTXjvfc5N_hFlNh0yhH5PbmIe8zCzsfzLMw6L6cKZXUrr6prI0

13 posted on 12/12/2021 11:24:50 PM PST by KTM rider (The COVID 19 scam is simply TERRORISM )
[ Post Reply | Private Reply | To 11 | View Replies]

To: KTM rider

No.


14 posted on 12/13/2021 12:14:24 AM PST by TexasGunLover
[ Post Reply | Private Reply | To 13 | View Replies]

To: blueplum
We've been at it (fortune 100 company) all weekend 24/7.

We have over 60k VM's with the vulnerability for over 14k applications.
15 posted on 12/13/2021 12:15:32 AM PST by TexasGunLover
[ Post Reply | Private Reply | To 1 | View Replies]

To: vikingd00d

Thnx for providing such a clear explanation for a semi-techie like me!


16 posted on 12/13/2021 1:04:46 AM PST by Mr Radical (In times of universal deceit, telling the truth is a revolutionary act)
[ Post Reply | Private Reply | To 7 | View Replies]

To: vikingd00d

I was thinking the same thing. What purpose could it serve?


17 posted on 12/13/2021 1:06:54 AM PST by gitmo (If your theology doesn't become your biography, what good is it?)
[ Post Reply | Private Reply | To 3 | View Replies]

To: TexasGunLover

It’s been impossible here to create new ebay listings via desktop since Friday (apparently ok via mobile apps), wonder if there could be a connection?


18 posted on 12/13/2021 1:08:25 AM PST by Mr Radical (In times of universal deceit, telling the truth is a revolutionary act)
[ Post Reply | Private Reply | To 15 | View Replies]

To: blueplum

bookmark


19 posted on 12/13/2021 1:24:37 AM PST by GOP Poet (Super cool you can change your tag line EVERYTIME you post!! :D. (Small things make me happy))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mr Radical

No.


20 posted on 12/13/2021 1:42:20 AM PST by TexasGunLover
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-31 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson