[Immit to imitation] When server connection to Micro is connected to DOOM... Abuse case of Apache Log4J with vulnerability was confirmed
: This article contains the introduction of the content that uses the program's vulnerability. Please do not imitate.
Java-based log output library Apache log4j that was announced on December 10, 2021. Using this vulnerability, the video that connects to the server with the Java version Main Craft has been released when DOOM can be played.
Apache Log4j has a zero-day vulnerability that may run any command by sending data that a remote third party may be crafted. The target version is 2.15.0 and the shipping candidate version 2.15.0-RC1, and the website of the Information Processing Promotion Organization (IPA) is also available for updating to the latest version.
This service is also used by the Java version Main Craft, so we are also calling attention to Japan official Twitter. Currently, the latest versions in the update are well-received, and we introduce measures for older versions of server and download files.
It is a very dangerous act to use vulnerabilities. Do not imitate and make an update to the latest version.
Comments
Post a Comment