Settings

Theme

Finding the log4j RCE With Fuzzing

code-intelligence.com

1 points by lrngjcb 4 years ago · 1 comment

Reader

lrngjcbOP 4 years ago

Hindsight is 20/20, but with a hook on javax.naming.Context#lookup and a generally useful improvement to the Map instrumentation, Jazzer reliably finds #log4j CVE-2021-44228 in ~5 min with a one-line fuzz target: log.error(data.consumeRemainingAsString());

https://github.com/CodeIntelligenceTesting/jazzer/pull/257

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection