Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Understanding Log4Shell RCE via writing an Exploit that applies a patch (lunasec.io)
3 points by freeqaz on Dec 16, 2021 | hide | past | favorite | 1 comment


This is a technical analysis of the Log4Shell exploit payload that we published the other day.

I wanted to use it as a moment to help others understand what this exploit is and how they could build it themselves to hopefully make mitigating this easier too.

I'm going to go finish up adding a section on how to decompile the compiled byte code back into Java code that you can read. I'll add that in a few mins to the post.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: