Light

Episode #849 Quiz

Log4j & Log4Shell
Date: 2021-12-14 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

The episode explains Log4Shell, CVE-2021-44228, a CVSS 10.0 remote-code-execution flaw in Log4j 2’s JNDI lookup feature. Malicious strings in logged input trigger LDAP/DNS lookups, fetching attacker code or secrets. Mitigation requires upgrading to Log4j 2.15.0, disabling lookups, and testing exposure with benign probes.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the core mistake in Log4j’s JNDI support that made Log4Shell possible?
Question 2: Which input pattern did Microsoft cite as a common way attackers triggered Log4Shell in logs?
Question 3: How did the Quebec government respond to the Log4j threat before it knew which systems were affected?
Question 4: What did the Huntress Log4Shell testing page do when a vulnerable application made the test lookup?
Question 5: Which combination of WordPress changes did the attackers use after exploiting the vulnerable plugins and themes?
Cancel