Website Security & Threat Management
Actual CVE-2021-44228 payloads captured in the wild

Actual CVE-2021-44228 payloads captured in the wild

12/10/2021 · John Graham-Cumming

What this post added

This post details the analysis of actual exploit payloads captured in the wild for the Log4Shell vulnerability (CVE-2021-44228). It provides statistics on blocked exploit requests per minute, the number of actively scanning IP addresses, and the geographical origins of these attacks. The post categorizes and analyzes various payload types, including reconnaissance attempts, User-Agent exploits, and evasion techniques using Log4j features like `${lower}`. It also highlights the use of DNS and Java/Linux command-line tools in some attacks, and the ongoing efforts by Cloudflare's security teams to update WAF and firewall rules in response to evolving exploit attempts.

Read the original post ↗