Log4Shell: How We Protect Users

General News

Summary

Here is a diagram of the attack chain from the Swiss Government Computer Emergency Response Team (GovCERT). The Log4j 2 vulnerability can be exploited by sending a log message with a specially crafted URI, which can cause the application to execute arbitrary code (such as by providing a Base64 encoded script in the path). You should find all systems and software using log4j in your environment (this can be a time-consuming task, so better start early) and check what version they’re using. Here’s a list by the Nationaal Cyber Security Centrum of the Netherlands in which you can check if software you are using is affected. Some JVM versions already have this as default setting • You may check for exploitation attempts — no matter whether they were successful or not — in your web server logs using the following Linux/Unix command: For more information on how to proceed regarding this exploit, check out the Swiss Government Computer Emergency Response Team (GovCERT) webpage.

Classifications

industries
No industries detected
applications
Business Intelligence

AskAI Classifications

Labels
Software Product SaaS IT Monitoring

Linked Companies

Sematext
$1M to $5M
GitHub, Inc.
$1M to $5M