No video

Log4Shell: The Movie... Why your sysadmins are working into the holidays

  Рет қаралды 9,542

Naked Security

Naked Security

Күн бұрын

Log4Shell is an infamous security hole - actually, three different bugs - affecting millions of servers around the world. Find out why your sysadmins and cybersecurity staff are "taking three for the team" just as holiday season starts...
news.sophos.co...
nakedsecurity....
news.sophos.co...

Пікірлер: 8
@papanito4802
@papanito4802 2 жыл бұрын
Excellent video, step by step into the misery. Very informative.
@bubblespawn
@bubblespawn 2 жыл бұрын
Excellent video, thanks Paul
@envoycdx
@envoycdx Жыл бұрын
Cheers.
@ProTechShow
@ProTechShow 2 жыл бұрын
Great demo. Very clear and easy to follow.
@GillesVolluzGasdia
@GillesVolluzGasdia 2 жыл бұрын
Excellent video, thanks Paul!
@leparrainrom2881
@leparrainrom2881 2 жыл бұрын
Nice, do you have somewhere the source code of your html page ?
@NakedSecurityBySophos
@NakedSecurityBySophos 2 жыл бұрын
-- Run via ncat, something like this: -- -- > ncat-vv -l 7777 --lua-exec fauxlogger.lua -- -- faulogger.lua-- local function trim(r) return r:gsub('%s*(.*)%s*$','%1') end local function getl() return trim(io.read('*l')) end local function putl(s) io.write(s,' ') io.flush() end local function putraw(s) io.write(s) io.flush() end local function say(f,...) io.stderr:write(string.format(f,...),' ') io.stderr:flush() end say '' local h = getl() say('--COMMAND: %s',h) local f = h:match('GET /%?Phone=(.*) HTTP/1%.1') if not f then putl 'HTTP/1.1 418 Cannot fill teapot' putl 'Connection: close' putl '' say(' ERROR: 418 Cannot fill teapot') return end f = f:gsub('%%(%x%x)',function(s) return string.char(tonumber(s,16)) end) say('--PHONE NO: [%s]',f) -- Read headers (stop at blank line) for i=1,99 do local r = getl() if r == '' then break end end -- Deal with data putl 'HTTP/1.1 200 OK' putl 'Connection: close' putl 'Content-Type: text/html' putl '' putl 'Submitted' -- Log it say '--LOGGING VIA JAVA:' os.execute('java TryLogger.java "'..f..'" 1>&2') say '==========' say ''
@leparrainrom2881
@leparrainrom2881 2 жыл бұрын
@@NakedSecurityBySophos Thanks !
I forced EVERYONE to use Linux
22:59
NetworkChuck
Рет қаралды 472 М.
HAFNIUM explained in plain English
21:07
Naked Security
Рет қаралды 1,7 М.
The Joker kisses Harley Quinn underwater!#Harley Quinn #joker
00:49
Harley Quinn with the Joker
Рет қаралды 19 МЛН
هذه الحلوى قد تقتلني 😱🍬
00:22
Cool Tool SHORTS Arabic
Рет қаралды 56 МЛН
Пройди игру и получи 5 чупа-чупсов (2024)
00:49
Екатерина Ковалева
Рет қаралды 4,3 МЛН
The Unreasonable Effectiveness Of Plain Text
14:37
No Boilerplate
Рет қаралды 599 М.
A DAY (NIGHT) in the LIFE of a NOC ENGINEER!
12:36
Custodian Data Centres
Рет қаралды 1,8 МЛН
THE UNTOLD STORY: How the PIX Firewall and NAT Saved the Internet
21:50
The Serial Port
Рет қаралды 379 М.
Tracking Cybercrime on Telegram
23:26
John Hammond
Рет қаралды 334 М.
What if my password manager gets hacked?
21:08
Naked Security
Рет қаралды 7 М.
Detect Hackers & Malware on your Computer (literally for free)
16:38
2 USB boot drives EVERY PC user should make before it's too late!
8:48
Ask Your Computer Guy
Рет қаралды 1,5 МЛН
Coding a Web Server in 25 Lines - Computerphile
17:49
Computerphile
Рет қаралды 334 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,2 МЛН