Workspace IndexDev Notes › Log4Shell — a logging line that executes attacker code

#175PoC

Log4Shell — a logging line that executes attacker code

The Log4j zero-day (CVE-2021-44228) turned a logged string into remote code execution across half the internet, the canonical lesson that a dependency's feature is your attack surface.

Not yet scoped.

Why

The PoC studies the JNDI-lookup mechanism in a sandbox and the patch timeline, treating 'what does logging even do' as the security question the incident forced everyone to ask.

How it works

Not yet built.

← All Dev Notes · Workspace Index · Top ↑

Log4Shell — 공격자 코드를 실행하는 로그 한 줄

Log4j 제로데이(CVE-2021-44228)는 로그에 남긴 문자열을 인터넷 절반에서 원격 코드 실행으로 바꿨으며, 의존성의 기능이 곧 내 공격 표면이라는 정전급 교훈입니다.

아직 범위 미정.

이 PoC는 샌드박스에서 JNDI 조회 메커니즘과 패치 타임라인을 연구하며, '로그가 대체 무엇을 하는가'를 이 사건이 모두에게 강제한 보안 질문으로 다룹니다.

동작 방식

아직 만들지 않음.

← 전체 개발 노트 · 워크스페이스 인덱스 · 맨 위 ↑