Analyzing a Log4j Exploit with Wireshark (and how to filter for it) // Sample PCAP!

  Рет қаралды 43,233

Chris Greer

Chris Greer

Күн бұрын

Пікірлер: 151
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Let's get some hands-on with Log4j! Download the pcap in the description and follow along. We'll look at how the attack works, how to filter for it, and how to config Wireshark to see where it is coming from. Hope you all enjoy and thank you so much for watching! I appreciate the comments and feedback.
@KaySwiss21
@KaySwiss21 2 жыл бұрын
I'm curious to know what you think about Intel ME. There's some claims that ME is spyware from Intel. Do you think it's more of a risk or benefit to keep ME, being there's a way to disable it with me_cleaner
@plushplush7635
@plushplush7635 2 жыл бұрын
thanks bro
@Devopscreator
@Devopscreator 2 жыл бұрын
Hi Chris, It's been 2 years since I started following you. Thanks for making such great video and your video are always to the point, short, simple and easy to understand. No one has explained the Wireshark better than you do. And it really helped in troubleshooting network issues.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
I appreciate that! Thanks for the comment!
@yogeshkhurana5014
@yogeshkhurana5014 2 жыл бұрын
I am in TAC for a switch company. This came to us as an vulnerability issue with device. But thankfully no device was vulnerable. And from video I got chance to know about this attack. Thank you..
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Great to hear. Thanks for the feedback!
@clementyves6154
@clementyves6154 2 жыл бұрын
Very nice video ! Good references and a lot of stuff learned again ! thanks for your job.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks!
@vq8gef32
@vq8gef32 Жыл бұрын
Amazing Chris. As always awesome. I liked the way you checked to make sure the server hasn't reacted. (was my question)
@hackebeil20
@hackebeil20 2 жыл бұрын
Chris, sincerely, there has not been a single video from you that didn't provide massive value to me! Just learned about cyberchef and virustotal - great tools, man!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Awesome! Yeah those two are VERY useful. Glad the video helped. I'll be posting another as soon as I can get my hands on that script. Stay tuned!
@NarendraS
@NarendraS 2 жыл бұрын
You are AMAZING!!!!! The quality and the content and the way you explain is top notch
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thank you!
@309Jolly
@309Jolly 2 жыл бұрын
Thanks for the info. We are bombarded with tickets and I can now understand whats cooking in the backend
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad it was helpful! More to come about this vuln as I get more pcaps.
@vnthks
@vnthks 2 жыл бұрын
Thank you Chris, for providing such an incredible packet analysis. Keep up the great work.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks, will do!
@letsgopacket4419
@letsgopacket4419 2 жыл бұрын
By watching your videos I realised how important the wireshark is..
@andyh3970
@andyh3970 2 жыл бұрын
Excellent pace and details- 11/10 !
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thank you Andy!
@chrishuston4445
@chrishuston4445 2 жыл бұрын
Amazingly helpful video, thank you for your time putting this together.
@hadestech8147
@hadestech8147 2 жыл бұрын
Chris, outstanding lesson. Thanks for the update.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
My pleasure!
@TNothingFree
@TNothingFree 2 жыл бұрын
Wonderful commentary, useful examples and short video. Very well done
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad you liked it! Thank you for the comment.
@songtrush2711
@songtrush2711 2 жыл бұрын
Wow. I am flashed. This is great (and nicely cat assisted) content. Glad I discovered your channel.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
😂 I was wondering when someone would comment on my cat.
@derrickdike5709
@derrickdike5709 2 жыл бұрын
Another incredible video with a lot of knowledge to help with analysis. Thanks Chris
@ChrisGreer
@ChrisGreer 2 жыл бұрын
My pleasure Derrick!
@mystiqkc
@mystiqkc 2 жыл бұрын
You are awesome. The way you explain things is clear and I feel excited to learn more. Thanks a lot for this. I have set a goal for myself to complete your Pluralsight courses for the coming holidays :-)
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Awesome! Reach out if you have any questions.
@faran_siddiqui-d3t
@faran_siddiqui-d3t 2 жыл бұрын
Wow just about to suggest you this idea. You read my mind sir !!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
We were thinking the same thing... I just had to get my hands on the pcap!
@vyasG
@vyasG 2 жыл бұрын
A ton of useful information in this video! Thank you.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks Vyas!
@RyanBess
@RyanBess 2 жыл бұрын
Look forward to seeing the next video on log4j. I too want to see the shell code
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks for the comment Ryan. No kidding! I do too... as soon as I can get my hands on a clean, share-able pcap I will get the video out.
@DynastyKiller__
@DynastyKiller__ 2 жыл бұрын
This is awesome work, Chris. Thanks for this video.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks for the comment Jorge!
@kiranjoshi6721
@kiranjoshi6721 2 жыл бұрын
Thanks!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thank you so much Kiran!
@venkatesh4760
@venkatesh4760 2 жыл бұрын
Hey Chris thanks for this great informative video ..
@shawn8163
@shawn8163 2 жыл бұрын
This is exactly right and if this was successful you could see the same dest port outbound as in the Jdni request in your example 1389
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Nice detail! Thanks for sharing.
@vishalpandita9857
@vishalpandita9857 2 жыл бұрын
Very helpful video with simple explanation. Thanks!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad it was helpful!
@jjames7206
@jjames7206 2 жыл бұрын
That's very useful, so smart!! Chris
@ThePumbaadk
@ThePumbaadk 2 жыл бұрын
Thanks Chris, this was great and with very good explanations
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thank you!
@alandoran
@alandoran 2 жыл бұрын
Thanks for sharing this Chris. Very helpful.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad it was helpful!
@deepaknarayanan3619
@deepaknarayanan3619 2 жыл бұрын
Woww Most Needed Content for current Situation ❤️👌 Much Appreciated video
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks for the comment!
@joepereira8690
@joepereira8690 2 жыл бұрын
This is great. Thank you for sharing.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
You are so welcome!
@petrprochazka7891
@petrprochazka7891 2 жыл бұрын
Thank you very much for such excelent video and very useful links.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
You are welcome!
@msa3218
@msa3218 2 жыл бұрын
Thanks a lot from Egypt keep your great work !!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks, will do!
@haogedeng8842
@haogedeng8842 2 жыл бұрын
Very informative - thank you very much for sharing!!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad it was helpful!
@MrBitviper
@MrBitviper 2 жыл бұрын
awesome video chris.. thank you so much
@GaryHammell
@GaryHammell 2 жыл бұрын
Great explanations and pace!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad you liked it! It's always hard to strike a balance in pacing. Keep the advanced folks interested while not losing the new folks. Thank you for the comment.
@FRD-HDD
@FRD-HDD 2 жыл бұрын
Very insightful. Thank you.
@yuvarajlakshmanan767
@yuvarajlakshmanan767 2 жыл бұрын
Great video at right time!. Thanks a lot.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad it was helpful!
@edisontan2440
@edisontan2440 2 жыл бұрын
Incredible video !👍🏻
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks a lot!
@peterborcik322
@peterborcik322 2 жыл бұрын
Man ! You are really cool ! Best wireshark stuff ever ;-)👍👍👍
@peterborcik322
@peterborcik322 2 жыл бұрын
I need one monitor extra for this wireshark map ;-)
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks! 👍
@zahidjaan1319
@zahidjaan1319 2 жыл бұрын
Good work, hope we will get more informative videos, like,subscribed !!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks!
@FayOnis
@FayOnis 2 жыл бұрын
thank you for this video, very knowledgable
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks Fay!
@benhartsimbolon6457
@benhartsimbolon6457 2 жыл бұрын
Very nice video. Really like the explanation !!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad you liked it!
@Seansaighdeoir
@Seansaighdeoir 2 жыл бұрын
Great job Chris many thanks for this.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
You are welcome! More to come as I get more pcaps!
@tweedle634
@tweedle634 2 жыл бұрын
Your content. is AMAZING. THANK YOU FOR THIS!!!!!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad you enjoy it!
@malkeetkalera7520
@malkeetkalera7520 2 жыл бұрын
I'm waiting for this
@compeec
@compeec 2 жыл бұрын
Thank you Chris, Good explanation.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad it was helpful!
@triumphant_54
@triumphant_54 Жыл бұрын
hi Chris, i saw your Wireshark course on David Bombal Training platform. do you offer certification for it?
@wingman2k
@wingman2k 2 жыл бұрын
Wow this is such a great video
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks!
@roarman75
@roarman75 2 жыл бұрын
Well explained.. nice!
@kevinaltizer
@kevinaltizer 2 жыл бұрын
Great info Chris. Thanks.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks for the comment Kevin!
@penguin--_--
@penguin--_-- 2 жыл бұрын
Hi Chris, Why my wireshark is only capturing 802.11 packets?
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hey - can you tell me a bit more about exactly what you see? by 802.11 do you mean control and mgt frames?
@ohkay8939
@ohkay8939 2 жыл бұрын
Awesome video, thank you.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad you liked it!
@dedkeny
@dedkeny 2 жыл бұрын
FYI the IP in the Base64 encoded message is still active... the IP may not be static but I found this interesting.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hmmmm, nice. Thanks for the comment!
@chockalingamchidambaram1948
@chockalingamchidambaram1948 2 жыл бұрын
Thanks for the video. Very informative. Do you know what is in that script that this attack is trying to execute (which you said opens up a connection back to the attacking host). Did you get a copy of that lh.sh script?
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hey! This particular one wasn't captured. However I did get my hands on a pcap with a similar attack and the script was captured too. I'm prepping the content for that video now. Stay tuned!
@chockalingamchidambaram1948
@chockalingamchidambaram1948 2 жыл бұрын
@@ChrisGreer Thanks !
@JoeClyde579
@JoeClyde579 Жыл бұрын
Great video
@SoulJah876
@SoulJah876 2 жыл бұрын
Very cool video, thank you.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Glad you liked it!
@kevingendron5586
@kevingendron5586 2 жыл бұрын
Excellent!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Many thanks! Glad you liked it!
@bhaskarmallarapu2392
@bhaskarmallarapu2392 2 жыл бұрын
Thank you, good video
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thank you too!
@KeaYeshua
@KeaYeshua 2 жыл бұрын
Nice one
@ShadyNetworker
@ShadyNetworker 2 жыл бұрын
Thanks for making the video! Is there anything you can share about the shell script referenced?
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Not much yet - but the more I learn the more I will share. Thanks for the comment!
@GiorgioCamozzi
@GiorgioCamozzi 2 жыл бұрын
Very interesting! Would it be possible for the server being attacked to initiate a connection back to the malicious IP through UDP? Or is wget always with TCP? Because then the server wouldn't do a SYN (as far as I'm aware it doesn't with UDP) and we would also need to filter for UDP connections originating from the attacked server.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hey Giorgio! So the server could totally start a stream back to the callback server, no rules against that. It may use another utility to do so however. I haven't tried using wget over UDP so I'm not sure on that one.
@GiorgioCamozzi
@GiorgioCamozzi 2 жыл бұрын
@@ChrisGreer Thanks Chris!:)
@HariKrishna-mw2rr
@HariKrishna-mw2rr 2 жыл бұрын
Thank you 😊
@ChrisGreer
@ChrisGreer 2 жыл бұрын
You're welcome 😊
@HashirrRoblox
@HashirrRoblox 2 жыл бұрын
Chris you are a good teacher 😀 Question why my Wireshark don't show the option for map it is grayed out ?
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Do you have the geoIP databases loaded?
@Abdelilahjghii
@Abdelilahjghii 2 жыл бұрын
Good ☺️
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thanks 😊
@washburnlane
@washburnlane 2 жыл бұрын
Thank you 🤘😎
@ChrisGreer
@ChrisGreer 2 жыл бұрын
No problem!
@chrismachabee3128
@chrismachabee3128 2 жыл бұрын
Thanks for the video. I'm a web designer. I have some Wireshark courses on thee shelf but, never got to them. watching an expert at the craft was very enliightening. It's funny too. I have been hearing of this Log4J thing I thought it was another language, until a day or so ago I hear that it is a malware. Not really my thing, but important nonetheless. I don;t think I would have been bored had you shared more details, but I understand. Can you tell by loking at that hack if it is s script kiddie or a major attempt? Thanks again.
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hey Chris thanks for the comment. I was able to get my hands on a pcap with more detail, so I plan to release a follow-on video soon. Stay tuned!
@chrismachabee3128
@chrismachabee3128 2 жыл бұрын
@@ChrisGreer Sure, sure, I subbed for sure. I have also a ethical hacker course. I really have to fit in with everything else I'm trying to wrap my head. We standing by.
@Avinashahn
@Avinashahn 2 жыл бұрын
Nice
@germancastillo681
@germancastillo681 2 жыл бұрын
Hi from Colombia @Chris, could you give us a clue on how to tshoot this in wireshark but not for http (port 80) but for https (port 443) conections?
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Hey German, good question! So the outbound TCP SYN filter would still work. I would probably add "!ip.dst==10.0.0.0/8" or whatever my internal address range was. Just because even though I might miss lateral movement from the server, I would definitely catch anytime it is going external to connect to somebody out there. I'd also keep a close eye on the number of small https connections that are made and the payload sizes. The post is a TCP connection all its own and is just a quick exchange. If I saw that behavior, followed by the server connecting externally, that would be suspect.
@S2eedGH
@S2eedGH 2 жыл бұрын
Thanks for great content, I tried GeoIP on Kali linux but when I click "open in browser" it shows blank page
@ChrisGreer
@ChrisGreer 2 жыл бұрын
I wonder if it is the way the file is being unzipped?
@majiddehbi9186
@majiddehbi9186 2 жыл бұрын
thx Chris just a question is it useful to the level of ccna200-301 thx
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Great question. I think it is great info for a CCNA to know, but it will not be on the exam. As far as TCP and Wireshark goes, the exam is very light on the details.
@aga01
@aga01 2 жыл бұрын
🔥
@AmazingJayB51
@AmazingJayB51 2 жыл бұрын
I downloaded the trace packet but how do you view or open it in WireShark?
@ChrisGreer
@ChrisGreer 2 жыл бұрын
I usually just double click it, or find it from within the Wireshark user interface.
@AmazingJayB51
@AmazingJayB51 2 жыл бұрын
@@ChrisGreer Thank you!
@plushplush7635
@plushplush7635 2 жыл бұрын
wooow so cool
@domagoj19zg
@domagoj19zg 2 жыл бұрын
Cool stuf
@TamazghaLandOfGod
@TamazghaLandOfGod 2 жыл бұрын
اللي جا من عند أمين رغيب Amine Raghib إعفط على جييييم نحسبكم 👍👍
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Welcome!
@WokwithLan
@WokwithLan 2 жыл бұрын
Wokwithlan here
@stadingschool9054
@stadingschool9054 2 жыл бұрын
Pub rarib Amin😂😂
@saidibra9231
@saidibra9231 2 жыл бұрын
you are going very fast, try to explain slowly
@Black_Swan68761
@Black_Swan68761 2 жыл бұрын
Thank you so much, Chris, for sharing this video. You explained it very well. Much appreciated!!!
@mystiqkc
@mystiqkc 2 жыл бұрын
Thanks!
@ChrisGreer
@ChrisGreer 2 жыл бұрын
Thank you!
MALWARE Analysis with Wireshark // TRICKBOT Infection
14:53
Chris Greer
Рет қаралды 49 М.
Из какого города смотришь? 😃
00:34
МЯТНАЯ ФАНТА
Рет қаралды 2,5 МЛН
А я думаю что за звук такой знакомый? 😂😂😂
00:15
Денис Кукояка
Рет қаралды 4,3 МЛН
If people acted like cats 🙀😹 LeoNata family #shorts
00:22
LeoNata Family
Рет қаралды 18 МЛН
Wireshark Practice - Hands-On
28:28
Chris Greer
Рет қаралды 11 М.
How TCP RETRANSMISSIONS Work // Analyzing Packet Loss
9:26
Chris Greer
Рет қаралды 58 М.
How ARP Poisoning Works // Man-in-the-Middle
13:29
Chris Greer
Рет қаралды 70 М.
Wireshark Tutorial // Fixing SLOW APPLICATIONS
8:43
Chris Greer
Рет қаралды 50 М.
How to know if your PC is hacked? Suspicious Network Activity 101
10:19
The PC Security Channel
Рет қаралды 1,3 МЛН
Strange File in Downloads Folder? Gootloader Malware Analysis
30:20
John Hammond
Рет қаралды 827 М.
Hands-On Traffic Analysis with Wireshark - Let's practice!
51:04
Chris Greer
Рет қаралды 38 М.
How IP FRAGMENTATION Works
14:41
Chris Greer
Рет қаралды 50 М.
Из какого города смотришь? 😃
00:34
МЯТНАЯ ФАНТА
Рет қаралды 2,5 МЛН