Apache Log4j 是一个 Java的日志记录库,Log4j 2 较 Log4j 1.x 有较大改进。
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
log4j-scanner is a project derived from other members of the open-source community by CISA to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities.
A community sourced list of log4j-affected software
log4j 漏洞扫描工具,可扫描指定文件夹也可作为Go包导入分析Jar文件
log4jdbc is a Java JDBC driver that can log SQL and/or JDBC calls (and optionally SQL timing information) for other JDBC drivers using the Simple Logging Facade For Java (SLF4J) logging system.
Remote Code Injection In Log4j
Log4j for nuclei
Log4j jndi injects the Payload generator
Log4j Vulnerability Scanner for Windows
Hashes for vulnerable LOG4J versions
Apache Log4j 远程代码执行
Simple local scanner for vulnerable log4j instances
Remote command execution vulnerability scanner for Log4j.
A Log4j writeup and Docker based PoC written in PowerShell
log4j漏洞靶场docker-compose
apache log4j poc—— base Maven
Operational information regarding the log4shell vulnerabilities in the Log4j logging library.
Tools for investigating Log4j CVE-2021-44228
Apache-Log4j漏洞复现笔记