Episode #854 Quiz
Anatomy of a Log4j Exploit
Date: 2022-01-18 | Length: 1.75 hrs | Episode page at twit.tv
About this episode
Log4j’s JNDI lookup lets crafted log strings trigger LDAP retrieval of malicious Java classes, yielding code execution. Governments and researchers rapidly scanned for vulnerable assets, while new bug bounty efforts found and remediated exposed systems. Attackers weaponized the flaw with PowerShell loaders, C2 polling, encrypted modules, and cleanup routines.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.