Beware, your logs - how blocked log4shell, Spring4Shell etc requests can still lead to compromise
We've had quite a flurry of look-alike vulnerabilities recently - log4shell, Spring4Shell, Apache Commons Configuration CVE-2022-33980 - all of which center around how various frameworks parse inpu...
Updated Dec 12, 2022
Version 2.0AaronJB
SIRT
Joined November 05, 2007
AaronJB
Dec 13, 2022SIRT
Absoultely - log4shell, at least, gives you complete remote code execution on the target vulnerable server (say a logging server sitting behind the BIG-IP), so you are free to drop webshells, malware, reverse shells, pivot to other hosts etc - being exposed is very bad indeed!