Light

Episode #854 Quiz

Anatomy of a Log4j Exploit
Date: 2022-01-18 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Log4j’s JNDI lookup lets crafted log strings trigger LDAP retrieval of malicious Java classes, yielding code execution. Governments and researchers rapidly scanned for vulnerable assets, while new bug bounty efforts found and remediated exposed systems. Attackers weaponized the flaw with PowerShell loaders, C2 polling, encrypted modules, and cleanup routines.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What exact TCP port did the KCodes NetUSB kernel module listen on by default in the affected routers, making it reachable on the WAN interface as well as the LAN?
Question 2: Which two HTTP headers were introduced in Chrome’s Private Network Access implementation for preflight negotiation with private-network targets?
Question 3: What condition had to be enabled in IIS for the wormable HTTP trailer flaw to become reachable on Windows servers?
Question 4: What transport and file path did the Iranian Log4j exploit kit use to retrieve its main PowerShell payload after the initial JNDI callback?
Question 5: Which two WordPress plugins shared the same arbitrary site-options update flaw and were cited as affecting tens of thousands of sites?
Cancel