Let's get some hands-on with Log4j! Download the pcap in the description and follow along. We'll look at how the attack works, how to filter for it, and how to config Wireshark to see where it is coming from. Hope you all enjoy and thank you so much for watching! I appreciate the comments and feedback.
@KaySwiss213 жыл бұрын
I'm curious to know what you think about Intel ME. There's some claims that ME is spyware from Intel. Do you think it's more of a risk or benefit to keep ME, being there's a way to disable it with me_cleaner
@plushplush76352 жыл бұрын
thanks bro
@Devopscreator3 жыл бұрын
Hi Chris, It's been 2 years since I started following you. Thanks for making such great video and your video are always to the point, short, simple and easy to understand. No one has explained the Wireshark better than you do. And it really helped in troubleshooting network issues.
@ChrisGreer3 жыл бұрын
I appreciate that! Thanks for the comment!
@kiranjoshi67213 жыл бұрын
Thanks!
@ChrisGreer3 жыл бұрын
Thank you so much Kiran!
@NarendraS3 жыл бұрын
You are AMAZING!!!!! The quality and the content and the way you explain is top notch
@ChrisGreer3 жыл бұрын
Thank you!
@vq8gef32 Жыл бұрын
Amazing Chris. As always awesome. I liked the way you checked to make sure the server hasn't reacted. (was my question)
@hackebeil203 жыл бұрын
Chris, sincerely, there has not been a single video from you that didn't provide massive value to me! Just learned about cyberchef and virustotal - great tools, man!
@ChrisGreer3 жыл бұрын
Awesome! Yeah those two are VERY useful. Glad the video helped. I'll be posting another as soon as I can get my hands on that script. Stay tuned!
@vnthks2 жыл бұрын
Thank you Chris, for providing such an incredible packet analysis. Keep up the great work.
@ChrisGreer2 жыл бұрын
Thanks, will do!
@andyh39703 жыл бұрын
Excellent pace and details- 11/10 !
@ChrisGreer3 жыл бұрын
Thank you Andy!
@clementyves61543 жыл бұрын
Very nice video ! Good references and a lot of stuff learned again ! thanks for your job.
@ChrisGreer3 жыл бұрын
Thanks!
@derrickdike57093 жыл бұрын
Another incredible video with a lot of knowledge to help with analysis. Thanks Chris
@ChrisGreer3 жыл бұрын
My pleasure Derrick!
@songtrush27113 жыл бұрын
Wow. I am flashed. This is great (and nicely cat assisted) content. Glad I discovered your channel.
@ChrisGreer3 жыл бұрын
😂 I was wondering when someone would comment on my cat.
@mystiqkc3 жыл бұрын
You are awesome. The way you explain things is clear and I feel excited to learn more. Thanks a lot for this. I have set a goal for myself to complete your Pluralsight courses for the coming holidays :-)
@ChrisGreer3 жыл бұрын
Awesome! Reach out if you have any questions.
@chrishuston44453 жыл бұрын
Amazingly helpful video, thank you for your time putting this together.
@TNothingFree3 жыл бұрын
Wonderful commentary, useful examples and short video. Very well done
@ChrisGreer3 жыл бұрын
Glad you liked it! Thank you for the comment.
@yogeshkhurana50143 жыл бұрын
I am in TAC for a switch company. This came to us as an vulnerability issue with device. But thankfully no device was vulnerable. And from video I got chance to know about this attack. Thank you..
@ChrisGreer3 жыл бұрын
Great to hear. Thanks for the feedback!
@hadestech81473 жыл бұрын
Chris, outstanding lesson. Thanks for the update.
@ChrisGreer3 жыл бұрын
My pleasure!
@DynastyKiller__3 жыл бұрын
This is awesome work, Chris. Thanks for this video.
@ChrisGreer3 жыл бұрын
Thanks for the comment Jorge!
@309Jolly3 жыл бұрын
Thanks for the info. We are bombarded with tickets and I can now understand whats cooking in the backend
@ChrisGreer3 жыл бұрын
Glad it was helpful! More to come about this vuln as I get more pcaps.
@vyasG3 жыл бұрын
A ton of useful information in this video! Thank you.
@ChrisGreer3 жыл бұрын
Thanks Vyas!
@faran_siddiqui-d3t3 жыл бұрын
Wow just about to suggest you this idea. You read my mind sir !!
@ChrisGreer3 жыл бұрын
We were thinking the same thing... I just had to get my hands on the pcap!
@deepaknarayanan36193 жыл бұрын
Woww Most Needed Content for current Situation ❤️👌 Much Appreciated video
@ChrisGreer3 жыл бұрын
Thanks for the comment!
@venkatesh47603 жыл бұрын
Hey Chris thanks for this great informative video ..
@edisontan24403 жыл бұрын
Incredible video !👍🏻
@ChrisGreer3 жыл бұрын
Thanks a lot!
@GaryHammell3 жыл бұрын
Great explanations and pace!
@ChrisGreer3 жыл бұрын
Glad you liked it! It's always hard to strike a balance in pacing. Keep the advanced folks interested while not losing the new folks. Thank you for the comment.
@vishalpandita98573 жыл бұрын
Very helpful video with simple explanation. Thanks!
@ChrisGreer3 жыл бұрын
Glad it was helpful!
@ThePumbaadk3 жыл бұрын
Thanks Chris, this was great and with very good explanations
@ChrisGreer3 жыл бұрын
Thank you!
@alandoran3 жыл бұрын
Thanks for sharing this Chris. Very helpful.
@ChrisGreer3 жыл бұрын
Glad it was helpful!
@RyanBess3 жыл бұрын
Look forward to seeing the next video on log4j. I too want to see the shell code
@ChrisGreer3 жыл бұрын
Thanks for the comment Ryan. No kidding! I do too... as soon as I can get my hands on a clean, share-able pcap I will get the video out.
@jjames72063 жыл бұрын
That's very useful, so smart!! Chris
@letsgopacket44193 жыл бұрын
By watching your videos I realised how important the wireshark is..
@msa32183 жыл бұрын
Thanks a lot from Egypt keep your great work !!
@ChrisGreer3 жыл бұрын
Thanks, will do!
@peterborcik3222 жыл бұрын
Man ! You are really cool ! Best wireshark stuff ever ;-)👍👍👍
@peterborcik3222 жыл бұрын
I need one monitor extra for this wireshark map ;-)
@ChrisGreer2 жыл бұрын
Thanks! 👍
@HashirrRoblox2 жыл бұрын
Chris you are a good teacher 😀 Question why my Wireshark don't show the option for map it is grayed out ?
@ChrisGreer2 жыл бұрын
Do you have the geoIP databases loaded?
@petrprochazka78913 жыл бұрын
Thank you very much for such excelent video and very useful links.
@ChrisGreer3 жыл бұрын
You are welcome!
@joepereira86903 жыл бұрын
This is great. Thank you for sharing.
@ChrisGreer3 жыл бұрын
You are so welcome!
@benhartsimbolon64573 жыл бұрын
Very nice video. Really like the explanation !!
@ChrisGreer3 жыл бұрын
Glad you liked it!
@triumphant_54 Жыл бұрын
hi Chris, i saw your Wireshark course on David Bombal Training platform. do you offer certification for it?
@Seansaighdeoir3 жыл бұрын
Great job Chris many thanks for this.
@ChrisGreer3 жыл бұрын
You are welcome! More to come as I get more pcaps!
@penguin--_--3 жыл бұрын
Hi Chris, Why my wireshark is only capturing 802.11 packets?
@ChrisGreer3 жыл бұрын
Hey - can you tell me a bit more about exactly what you see? by 802.11 do you mean control and mgt frames?
@yuvarajlakshmanan7673 жыл бұрын
Great video at right time!. Thanks a lot.
@ChrisGreer3 жыл бұрын
Glad it was helpful!
@wingman2k3 жыл бұрын
Wow this is such a great video
@ChrisGreer3 жыл бұрын
Thanks!
@zahidjaan13193 жыл бұрын
Good work, hope we will get more informative videos, like,subscribed !!
@ChrisGreer3 жыл бұрын
Thanks!
@kevinaltizer3 жыл бұрын
Great info Chris. Thanks.
@ChrisGreer3 жыл бұрын
Thanks for the comment Kevin!
@FRD-HDD3 жыл бұрын
Very insightful. Thank you.
@MrBitviper3 жыл бұрын
awesome video chris.. thank you so much
@haogedeng88423 жыл бұрын
Very informative - thank you very much for sharing!!
@ChrisGreer3 жыл бұрын
Glad it was helpful!
@chockalingamchidambaram19483 жыл бұрын
Thanks for the video. Very informative. Do you know what is in that script that this attack is trying to execute (which you said opens up a connection back to the attacking host). Did you get a copy of that lh.sh script?
@ChrisGreer3 жыл бұрын
Hey! This particular one wasn't captured. However I did get my hands on a pcap with a similar attack and the script was captured too. I'm prepping the content for that video now. Stay tuned!
@chockalingamchidambaram19483 жыл бұрын
@@ChrisGreer Thanks !
@dedkeny2 жыл бұрын
FYI the IP in the Base64 encoded message is still active... the IP may not be static but I found this interesting.
@ChrisGreer2 жыл бұрын
Hmmmm, nice. Thanks for the comment!
@compeec3 жыл бұрын
Thank you Chris, Good explanation.
@ChrisGreer3 жыл бұрын
Glad it was helpful!
@tweedle6343 жыл бұрын
Your content. is AMAZING. THANK YOU FOR THIS!!!!!
@ChrisGreer3 жыл бұрын
Glad you enjoy it!
@ShadyNetworker3 жыл бұрын
Thanks for making the video! Is there anything you can share about the shell script referenced?
@ChrisGreer3 жыл бұрын
Not much yet - but the more I learn the more I will share. Thanks for the comment!
@GiorgioCamozzi2 жыл бұрын
Very interesting! Would it be possible for the server being attacked to initiate a connection back to the malicious IP through UDP? Or is wget always with TCP? Because then the server wouldn't do a SYN (as far as I'm aware it doesn't with UDP) and we would also need to filter for UDP connections originating from the attacked server.
@ChrisGreer2 жыл бұрын
Hey Giorgio! So the server could totally start a stream back to the callback server, no rules against that. It may use another utility to do so however. I haven't tried using wget over UDP so I'm not sure on that one.
@GiorgioCamozzi2 жыл бұрын
@@ChrisGreer Thanks Chris!:)
@FayOnis3 жыл бұрын
thank you for this video, very knowledgable
@ChrisGreer3 жыл бұрын
Thanks Fay!
@malkeetkalera75203 жыл бұрын
I'm waiting for this
@shawn81633 жыл бұрын
This is exactly right and if this was successful you could see the same dest port outbound as in the Jdni request in your example 1389
@ChrisGreer3 жыл бұрын
Nice detail! Thanks for sharing.
@chrismachabee31283 жыл бұрын
Thanks for the video. I'm a web designer. I have some Wireshark courses on thee shelf but, never got to them. watching an expert at the craft was very enliightening. It's funny too. I have been hearing of this Log4J thing I thought it was another language, until a day or so ago I hear that it is a malware. Not really my thing, but important nonetheless. I don;t think I would have been bored had you shared more details, but I understand. Can you tell by loking at that hack if it is s script kiddie or a major attempt? Thanks again.
@ChrisGreer3 жыл бұрын
Hey Chris thanks for the comment. I was able to get my hands on a pcap with more detail, so I plan to release a follow-on video soon. Stay tuned!
@chrismachabee31283 жыл бұрын
@@ChrisGreer Sure, sure, I subbed for sure. I have also a ethical hacker course. I really have to fit in with everything else I'm trying to wrap my head. We standing by.
@germancastillo6813 жыл бұрын
Hi from Colombia @Chris, could you give us a clue on how to tshoot this in wireshark but not for http (port 80) but for https (port 443) conections?
@ChrisGreer3 жыл бұрын
Hey German, good question! So the outbound TCP SYN filter would still work. I would probably add "!ip.dst==10.0.0.0/8" or whatever my internal address range was. Just because even though I might miss lateral movement from the server, I would definitely catch anytime it is going external to connect to somebody out there. I'd also keep a close eye on the number of small https connections that are made and the payload sizes. The post is a TCP connection all its own and is just a quick exchange. If I saw that behavior, followed by the server connecting externally, that would be suspect.
@ohkay89393 жыл бұрын
Awesome video, thank you.
@ChrisGreer3 жыл бұрын
Glad you liked it!
@majiddehbi91863 жыл бұрын
thx Chris just a question is it useful to the level of ccna200-301 thx
@ChrisGreer3 жыл бұрын
Great question. I think it is great info for a CCNA to know, but it will not be on the exam. As far as TCP and Wireshark goes, the exam is very light on the details.
@S2eedGH3 жыл бұрын
Thanks for great content, I tried GeoIP on Kali linux but when I click "open in browser" it shows blank page
@ChrisGreer3 жыл бұрын
I wonder if it is the way the file is being unzipped?
@AmazingJayB513 жыл бұрын
I downloaded the trace packet but how do you view or open it in WireShark?
@ChrisGreer3 жыл бұрын
I usually just double click it, or find it from within the Wireshark user interface.
@AmazingJayB513 жыл бұрын
@@ChrisGreer Thank you!
@JoeClyde579 Жыл бұрын
Great video
@roarman753 жыл бұрын
Well explained.. nice!
@washburnlane3 жыл бұрын
Thank you 🤘😎
@ChrisGreer3 жыл бұрын
No problem!
@HariKrishna-mw2rr3 жыл бұрын
Thank you 😊
@ChrisGreer3 жыл бұрын
You're welcome 😊
@bhaskarmallarapu23922 жыл бұрын
Thank you, good video
@ChrisGreer2 жыл бұрын
Thank you too!
@SoulJah8763 жыл бұрын
Very cool video, thank you.
@ChrisGreer3 жыл бұрын
Glad you liked it!
@kevingendron55862 жыл бұрын
Excellent!
@ChrisGreer2 жыл бұрын
Many thanks! Glad you liked it!
@Abdelilahjghii3 жыл бұрын
Good ☺️
@ChrisGreer3 жыл бұрын
Thanks 😊
@aga013 жыл бұрын
🔥
@levvyNok3 жыл бұрын
Nice one
@Avinashahn3 жыл бұрын
Nice
@plushplush76352 жыл бұрын
wooow so cool
@domagoj19zg3 жыл бұрын
Cool stuf
@WokwithLan3 жыл бұрын
Wokwithlan here
@stadingschool90543 жыл бұрын
Pub rarib Amin😂😂
@TamazghaLandOfGod3 жыл бұрын
اللي جا من عند أمين رغيب Amine Raghib إعفط على جييييم نحسبكم 👍👍
@ChrisGreer3 жыл бұрын
Welcome!
@saidibra92312 жыл бұрын
you are going very fast, try to explain slowly
@mystiqkc3 жыл бұрын
Thanks!
@ChrisGreer3 жыл бұрын
Thank you!
@Black_Swan687613 жыл бұрын
Thank you so much, Chris, for sharing this video. You explained it very well. Much appreciated!!!