Website Security & Threat Management
Exploitation of Log4j CVE-2021-44228 before public disclosure and evolution of evasion and exfiltration

Exploitation of Log4j CVE-2021-44228 before public disclosure and evolution of evasion and exfiltration

12/14/2021 · John Graham-Cumming, Celso Martinho

What this post added

This post details the real-time exploitation of CVE-2021-44228 (Log4Shell) observed by Cloudflare, including exploitation attempts prior to public disclosure. It analyzes WAF evasion patterns using Log4j's lookup language and standard encoding techniques, and provides examples of data exfiltration attempts. The post also presents trend data on blocked exploitation attempts and their geographical origins, highlighting the rapid evolution of attacker tactics and the need for robust WAF rule sets and system patching.

Read the original post ↗