Analyzing a Log4j Exploit with Wireshark (and how to filter for it) // Sample PCAP!

  Рет қаралды 43,859

Chris Greer

Chris Greer

Күн бұрын

Пікірлер: 151
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Let's get some hands-on with Log4j! Download the pcap in the description and follow along. We'll look at how the attack works, how to filter for it, and how to config Wireshark to see where it is coming from. Hope you all enjoy and thank you so much for watching! I appreciate the comments and feedback.
@KaySwiss21
@KaySwiss21 3 жыл бұрын
I'm curious to know what you think about Intel ME. There's some claims that ME is spyware from Intel. Do you think it's more of a risk or benefit to keep ME, being there's a way to disable it with me_cleaner
@plushplush7635
@plushplush7635 2 жыл бұрын
thanks bro
@Devopscreator
@Devopscreator 3 жыл бұрын
Hi Chris, It's been 2 years since I started following you. Thanks for making such great video and your video are always to the point, short, simple and easy to understand. No one has explained the Wireshark better than you do. And it really helped in troubleshooting network issues.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
I appreciate that! Thanks for the comment!
@kiranjoshi6721
@kiranjoshi6721 3 жыл бұрын
Thanks!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thank you so much Kiran!
@NarendraS
@NarendraS 3 жыл бұрын
You are AMAZING!!!!! The quality and the content and the way you explain is top notch
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thank you!
@vq8gef32
@vq8gef32 Жыл бұрын
Amazing Chris. As always awesome. I liked the way you checked to make sure the server hasn't reacted. (was my question)
@hackebeil20
@hackebeil20 3 жыл бұрын
Chris, sincerely, there has not been a single video from you that didn't provide massive value to me! Just learned about cyberchef and virustotal - great tools, man!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Awesome! Yeah those two are VERY useful. Glad the video helped. I'll be posting another as soon as I can get my hands on that script. Stay tuned!
@vnthks
@vnthks 2 жыл бұрын
Thank you Chris, for providing such an incredible packet analysis. Keep up the great work.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks, will do!
@andyh3970
@andyh3970 3 жыл бұрын
Excellent pace and details- 11/10 !
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thank you Andy!
@clementyves6154
@clementyves6154 3 жыл бұрын
Very nice video ! Good references and a lot of stuff learned again ! thanks for your job.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks!
@derrickdike5709
@derrickdike5709 3 жыл бұрын
Another incredible video with a lot of knowledge to help with analysis. Thanks Chris
@ChrisGreer
@ChrisGreer 3 жыл бұрын
My pleasure Derrick!
@songtrush2711
@songtrush2711 3 жыл бұрын
Wow. I am flashed. This is great (and nicely cat assisted) content. Glad I discovered your channel.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
😂 I was wondering when someone would comment on my cat.
@mystiqkc
@mystiqkc 3 жыл бұрын
You are awesome. The way you explain things is clear and I feel excited to learn more. Thanks a lot for this. I have set a goal for myself to complete your Pluralsight courses for the coming holidays :-)
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Awesome! Reach out if you have any questions.
@chrishuston4445
@chrishuston4445 3 жыл бұрын
Amazingly helpful video, thank you for your time putting this together.
@TNothingFree
@TNothingFree 3 жыл бұрын
Wonderful commentary, useful examples and short video. Very well done
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad you liked it! Thank you for the comment.
@yogeshkhurana5014
@yogeshkhurana5014 3 жыл бұрын
I am in TAC for a switch company. This came to us as an vulnerability issue with device. But thankfully no device was vulnerable. And from video I got chance to know about this attack. Thank you..
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Great to hear. Thanks for the feedback!
@hadestech8147
@hadestech8147 3 жыл бұрын
Chris, outstanding lesson. Thanks for the update.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
My pleasure!
@DynastyKiller__
@DynastyKiller__ 3 жыл бұрын
This is awesome work, Chris. Thanks for this video.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks for the comment Jorge!
@309Jolly
@309Jolly 3 жыл бұрын
Thanks for the info. We are bombarded with tickets and I can now understand whats cooking in the backend
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad it was helpful! More to come about this vuln as I get more pcaps.
@vyasG
@vyasG 3 жыл бұрын
A ton of useful information in this video! Thank you.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks Vyas!
@faran_siddiqui-d3t
@faran_siddiqui-d3t 3 жыл бұрын
Wow just about to suggest you this idea. You read my mind sir !!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
We were thinking the same thing... I just had to get my hands on the pcap!
@deepaknarayanan3619
@deepaknarayanan3619 3 жыл бұрын
Woww Most Needed Content for current Situation ❤️👌 Much Appreciated video
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks for the comment!
@venkatesh4760
@venkatesh4760 3 жыл бұрын
Hey Chris thanks for this great informative video ..
@edisontan2440
@edisontan2440 3 жыл бұрын
Incredible video !👍🏻
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks a lot!
@GaryHammell
@GaryHammell 3 жыл бұрын
Great explanations and pace!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad you liked it! It's always hard to strike a balance in pacing. Keep the advanced folks interested while not losing the new folks. Thank you for the comment.
@vishalpandita9857
@vishalpandita9857 3 жыл бұрын
Very helpful video with simple explanation. Thanks!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad it was helpful!
@ThePumbaadk
@ThePumbaadk 3 жыл бұрын
Thanks Chris, this was great and with very good explanations
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thank you!
@alandoran
@alandoran 3 жыл бұрын
Thanks for sharing this Chris. Very helpful.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad it was helpful!
@RyanBess
@RyanBess 3 жыл бұрын
Look forward to seeing the next video on log4j. I too want to see the shell code
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks for the comment Ryan. No kidding! I do too... as soon as I can get my hands on a clean, share-able pcap I will get the video out.
@jjames7206
@jjames7206 3 жыл бұрын
That's very useful, so smart!! Chris
@letsgopacket4419
@letsgopacket4419 3 жыл бұрын
By watching your videos I realised how important the wireshark is..
@msa3218
@msa3218 3 жыл бұрын
Thanks a lot from Egypt keep your great work !!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks, will do!
@peterborcik322
@peterborcik322 2 жыл бұрын
Man ! You are really cool ! Best wireshark stuff ever ;-)👍👍👍
@peterborcik322
@peterborcik322 2 жыл бұрын
I need one monitor extra for this wireshark map ;-)
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks! 👍
@HashirrRoblox
@HashirrRoblox 2 жыл бұрын
Chris you are a good teacher 😀 Question why my Wireshark don't show the option for map it is grayed out ?
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Do you have the geoIP databases loaded?
@petrprochazka7891
@petrprochazka7891 3 жыл бұрын
Thank you very much for such excelent video and very useful links.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
You are welcome!
@joepereira8690
@joepereira8690 3 жыл бұрын
This is great. Thank you for sharing.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
You are so welcome!
@benhartsimbolon6457
@benhartsimbolon6457 3 жыл бұрын
Very nice video. Really like the explanation !!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad you liked it!
@triumphant_54
@triumphant_54 Жыл бұрын
hi Chris, i saw your Wireshark course on David Bombal Training platform. do you offer certification for it?
@Seansaighdeoir
@Seansaighdeoir 3 жыл бұрын
Great job Chris many thanks for this.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
You are welcome! More to come as I get more pcaps!
@penguin--_--
@penguin--_-- 3 жыл бұрын
Hi Chris, Why my wireshark is only capturing 802.11 packets?
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Hey - can you tell me a bit more about exactly what you see? by 802.11 do you mean control and mgt frames?
@yuvarajlakshmanan767
@yuvarajlakshmanan767 3 жыл бұрын
Great video at right time!. Thanks a lot.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad it was helpful!
@wingman2k
@wingman2k 3 жыл бұрын
Wow this is such a great video
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks!
@zahidjaan1319
@zahidjaan1319 3 жыл бұрын
Good work, hope we will get more informative videos, like,subscribed !!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks!
@kevinaltizer
@kevinaltizer 3 жыл бұрын
Great info Chris. Thanks.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks for the comment Kevin!
@FRD-HDD
@FRD-HDD 3 жыл бұрын
Very insightful. Thank you.
@MrBitviper
@MrBitviper 3 жыл бұрын
awesome video chris.. thank you so much
@haogedeng8842
@haogedeng8842 3 жыл бұрын
Very informative - thank you very much for sharing!!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad it was helpful!
@chockalingamchidambaram1948
@chockalingamchidambaram1948 3 жыл бұрын
Thanks for the video. Very informative. Do you know what is in that script that this attack is trying to execute (which you said opens up a connection back to the attacking host). Did you get a copy of that lh.sh script?
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Hey! This particular one wasn't captured. However I did get my hands on a pcap with a similar attack and the script was captured too. I'm prepping the content for that video now. Stay tuned!
@chockalingamchidambaram1948
@chockalingamchidambaram1948 3 жыл бұрын
@@ChrisGreer Thanks !
@dedkeny
@dedkeny 2 жыл бұрын
FYI the IP in the Base64 encoded message is still active... the IP may not be static but I found this interesting.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hmmmm, nice. Thanks for the comment!
@compeec
@compeec 3 жыл бұрын
Thank you Chris, Good explanation.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad it was helpful!
@tweedle634
@tweedle634 3 жыл бұрын
Your content. is AMAZING. THANK YOU FOR THIS!!!!!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad you enjoy it!
@ShadyNetworker
@ShadyNetworker 3 жыл бұрын
Thanks for making the video! Is there anything you can share about the shell script referenced?
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Not much yet - but the more I learn the more I will share. Thanks for the comment!
@GiorgioCamozzi
@GiorgioCamozzi 2 жыл бұрын
Very interesting! Would it be possible for the server being attacked to initiate a connection back to the malicious IP through UDP? Or is wget always with TCP? Because then the server wouldn't do a SYN (as far as I'm aware it doesn't with UDP) and we would also need to filter for UDP connections originating from the attacked server.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hey Giorgio! So the server could totally start a stream back to the callback server, no rules against that. It may use another utility to do so however. I haven't tried using wget over UDP so I'm not sure on that one.
@GiorgioCamozzi
@GiorgioCamozzi 2 жыл бұрын
@@ChrisGreer Thanks Chris!:)
@FayOnis
@FayOnis 3 жыл бұрын
thank you for this video, very knowledgable
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks Fay!
@malkeetkalera7520
@malkeetkalera7520 3 жыл бұрын
I'm waiting for this
@shawn8163
@shawn8163 3 жыл бұрын
This is exactly right and if this was successful you could see the same dest port outbound as in the Jdni request in your example 1389
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Nice detail! Thanks for sharing.
@chrismachabee3128
@chrismachabee3128 3 жыл бұрын
Thanks for the video. I'm a web designer. I have some Wireshark courses on thee shelf but, never got to them. watching an expert at the craft was very enliightening. It's funny too. I have been hearing of this Log4J thing I thought it was another language, until a day or so ago I hear that it is a malware. Not really my thing, but important nonetheless. I don;t think I would have been bored had you shared more details, but I understand. Can you tell by loking at that hack if it is s script kiddie or a major attempt? Thanks again.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Hey Chris thanks for the comment. I was able to get my hands on a pcap with more detail, so I plan to release a follow-on video soon. Stay tuned!
@chrismachabee3128
@chrismachabee3128 3 жыл бұрын
@@ChrisGreer Sure, sure, I subbed for sure. I have also a ethical hacker course. I really have to fit in with everything else I'm trying to wrap my head. We standing by.
@germancastillo681
@germancastillo681 3 жыл бұрын
Hi from Colombia @Chris, could you give us a clue on how to tshoot this in wireshark but not for http (port 80) but for https (port 443) conections?
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Hey German, good question! So the outbound TCP SYN filter would still work. I would probably add "!ip.dst==10.0.0.0/8" or whatever my internal address range was. Just because even though I might miss lateral movement from the server, I would definitely catch anytime it is going external to connect to somebody out there. I'd also keep a close eye on the number of small https connections that are made and the payload sizes. The post is a TCP connection all its own and is just a quick exchange. If I saw that behavior, followed by the server connecting externally, that would be suspect.
@ohkay8939
@ohkay8939 3 жыл бұрын
Awesome video, thank you.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad you liked it!
@majiddehbi9186
@majiddehbi9186 3 жыл бұрын
thx Chris just a question is it useful to the level of ccna200-301 thx
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Great question. I think it is great info for a CCNA to know, but it will not be on the exam. As far as TCP and Wireshark goes, the exam is very light on the details.
@S2eedGH
@S2eedGH 3 жыл бұрын
Thanks for great content, I tried GeoIP on Kali linux but when I click "open in browser" it shows blank page
@ChrisGreer
@ChrisGreer 3 жыл бұрын
I wonder if it is the way the file is being unzipped?
@AmazingJayB51
@AmazingJayB51 3 жыл бұрын
I downloaded the trace packet but how do you view or open it in WireShark?
@ChrisGreer
@ChrisGreer 3 жыл бұрын
I usually just double click it, or find it from within the Wireshark user interface.
@AmazingJayB51
@AmazingJayB51 3 жыл бұрын
@@ChrisGreer Thank you!
@JoeClyde579
@JoeClyde579 Жыл бұрын
Great video
@roarman75
@roarman75 3 жыл бұрын
Well explained.. nice!
@washburnlane
@washburnlane 3 жыл бұрын
Thank you 🤘😎
@ChrisGreer
@ChrisGreer 3 жыл бұрын
No problem!
@HariKrishna-mw2rr
@HariKrishna-mw2rr 3 жыл бұрын
Thank you 😊
@ChrisGreer
@ChrisGreer 3 жыл бұрын
You're welcome 😊
@bhaskarmallarapu2392
@bhaskarmallarapu2392 2 жыл бұрын
Thank you, good video
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thank you too!
@SoulJah876
@SoulJah876 3 жыл бұрын
Very cool video, thank you.
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Glad you liked it!
@kevingendron5586
@kevingendron5586 2 жыл бұрын
Excellent!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Many thanks! Glad you liked it!
@Abdelilahjghii
@Abdelilahjghii 3 жыл бұрын
Good ☺️
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thanks 😊
@aga01
@aga01 3 жыл бұрын
🔥
@levvyNok
@levvyNok 3 жыл бұрын
Nice one
@Avinashahn
@Avinashahn 3 жыл бұрын
Nice
@plushplush7635
@plushplush7635 2 жыл бұрын
wooow so cool
@domagoj19zg
@domagoj19zg 3 жыл бұрын
Cool stuf
@WokwithLan
@WokwithLan 3 жыл бұрын
Wokwithlan here
@stadingschool9054
@stadingschool9054 3 жыл бұрын
Pub rarib Amin😂😂
@TamazghaLandOfGod
@TamazghaLandOfGod 3 жыл бұрын
اللي جا من عند أمين رغيب Amine Raghib إعفط على جييييم نحسبكم 👍👍
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Welcome!
@saidibra9231
@saidibra9231 2 жыл бұрын
you are going very fast, try to explain slowly
@mystiqkc
@mystiqkc 3 жыл бұрын
Thanks!
@ChrisGreer
@ChrisGreer 3 жыл бұрын
Thank you!
@Black_Swan68761
@Black_Swan68761 3 жыл бұрын
Thank you so much, Chris, for sharing this video. You explained it very well. Much appreciated!!!
MALWARE Analysis with Wireshark // TRICKBOT Infection
14:53
Chris Greer
Рет қаралды 51 М.
Is DECRYPTION really necessary?
18:21
Chris Greer
Рет қаралды 4,5 М.
Мясо вегана? 🧐 @Whatthefshow
01:01
История одного вокалиста
Рет қаралды 7 МЛН
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
Quando A Diferença De Altura É Muito Grande 😲😂
00:12
Mari Maria
Рет қаралды 45 МЛН
How ARP Poisoning Works // Man-in-the-Middle
13:29
Chris Greer
Рет қаралды 73 М.
How TCP RETRANSMISSIONS Work // Analyzing Packet Loss
9:26
Chris Greer
Рет қаралды 60 М.
Build a Firewall that tells Hackers to Try Harder
25:14
Gnar Coding
Рет қаралды 55 М.
How IP FRAGMENTATION Works
14:41
Chris Greer
Рет қаралды 52 М.
Solving a REAL investigation using OSINT
19:03
Gary Ruddell
Рет қаралды 219 М.
Wireshark - Malware traffic Analysis
16:01
Hack eXPlorer
Рет қаралды 207 М.
Decrypting HTTPS Traffic With Wireshark
15:49
HackerSploit
Рет қаралды 115 М.
How to know if your PC is hacked? Suspicious Network Activity 101
10:19
PC Security Channel
Рет қаралды 1,3 МЛН