
12/14/2021 · John Graham-Cumming, Celso Martinho
What this post added
This post details the real-time exploitation of CVE-2021-44228 (Log4Shell) observed by Cloudflare, including exploitation attempts prior to public disclosure. It analyzes WAF evasion patterns using Log4j's lookup language and standard encoding techniques, and provides examples of data exfiltration attempts. The post also presents trend data on blocked exploitation attempts and their geographical origins, highlighting the rapid evolution of attacker tactics and the need for robust WAF rule sets and system patching.