
12/10/2021 · John Graham-Cumming
What this post added
This post details the analysis of actual exploit payloads captured in the wild for the Log4Shell vulnerability (CVE-2021-44228). It provides statistics on blocked exploit requests per minute, the number of actively scanning IP addresses, and the geographical origins of these attacks. The post categorizes and analyzes various payload types, including reconnaissance attempts, User-Agent exploits, and evasion techniques using Log4j features like `${lower}`. It also highlights the use of DNS and Java/Linux command-line tools in some attacks, and the ongoing efforts by Cloudflare's security teams to update WAF and firewall rules in response to evolving exploit attempts.