Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Log4J

Log4J

Scheduled Pinned Locked Moved The Lounge
jsonquestion
18 Posts 15 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • abmvA abmv

    Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

    Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

    P Offline
    P Offline
    Peter_in_2780
    wrote on last edited by
    #2

    When I heard about it a bit over a week ago, I scanned all my file systems. The only bits that came close were some historical backups of long-dead machines. The first attempted exploit in my server logs was at 2021-12-11 00:28Z. Since then the "villains" are using all sorts of cute encoding tricks to get jndi past dumb filters that look for it in plain text. They account for currently around 7 or 8% of the noise traffic (i.e. by IP address, not hostname). And yes, I think there is a considerable "beatup" component. Apart from Minecraft, I haven't heard of any significant exploits.

    Software rusts. Simon Stephenson, ca 1994. So does this signature. me, 2012

    J 1 Reply Last reply
    0
    • abmvA abmv

      Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

      Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

      J Offline
      J Offline
      Jacquers
      wrote on last edited by
      #3

      Did a scan on my machine. IntelliJ Idea uses it.

      1 Reply Last reply
      0
      • abmvA abmv

        Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

        Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

        R Offline
        R Offline
        RickZeeland
        wrote on last edited by
        #4

        Where I work (Windows shop) we only have two candidates, TeamCity and Jira, both were not affected.

        1 Reply Last reply
        0
        • abmvA abmv

          Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

          Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

          S Offline
          S Offline
          Super Lloyd
          wrote on last edited by
          #5

          Well plenty of 1999 stuff is still running in production in plenty of places.. why changes something that is working hey?! AS400 and Cobol is much older and still widely in use! :O

          A new .NET Serializer All in one Menu-Ribbon Bar Taking over the world since 1371!

          1 Reply Last reply
          0
          • abmvA abmv

            Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

            Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

            pkfoxP Offline
            pkfoxP Offline
            pkfox
            wrote on last edited by
            #6

            I have a Linux Jenkins build server and whilst the Jenkins core doesn't use log4j the groovy scripting language does and possibly some plugins.

            "Life should not be a journey to the grave with the intention of arriving safely in a pretty and well-preserved body, but rather to skid in broadside in a cloud of smoke, thoroughly used up, totally worn out, and loudly proclaiming “Wow! What a Ride!" - Hunter S Thompson - RIP

            1 Reply Last reply
            0
            • abmvA abmv

              Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

              Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

              R Offline
              R Offline
              realJSOP
              wrote on last edited by
              #7

              Another reason not to blindly jump on any "new" framework, just because it's "new". BTW, my team is full of programming gods, and we don't do logging. At all.

              ".45 ACP - because shooting twice is just silly" - JSOP, 2010
              -----
              You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
              -----
              When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

              D 1 Reply Last reply
              0
              • abmvA abmv

                Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

                Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

                0 Offline
                0 Offline
                0x01AA
                wrote on last edited by
                #8

                I don't understand it... A logging library should simply log messages, right? How can a logging library become vulnerable? I think only if it does taking actions for specific messages. And that is not the job of a logging tool :doh: [Edit] Good explanation I found here: All About Log4j Log4Shell 0-Day Vulnerability - CVE-2021-44228[^]

                H 1 Reply Last reply
                0
                • 0 0x01AA

                  I don't understand it... A logging library should simply log messages, right? How can a logging library become vulnerable? I think only if it does taking actions for specific messages. And that is not the job of a logging tool :doh: [Edit] Good explanation I found here: All About Log4j Log4Shell 0-Day Vulnerability - CVE-2021-44228[^]

                  H Offline
                  H Offline
                  honey the codewitch
                  wrote on last edited by
                  #9

                  Any library can become vulnerable if it doesn't bounds check everything. Back when I was a youth - and I don't recommend this - I rooted a server using their print daemon. It *is* weird that it's happening with the JVM, given java code is managed and thus relatively hardened, but I don't know *anything* about the exploit so I can only speak about exploits in general.

                  Real programmers use butterflies

                  0 J 2 Replies Last reply
                  0
                  • H honey the codewitch

                    Any library can become vulnerable if it doesn't bounds check everything. Back when I was a youth - and I don't recommend this - I rooted a server using their print daemon. It *is* weird that it's happening with the JVM, given java code is managed and thus relatively hardened, but I don't know *anything* about the exploit so I can only speak about exploits in general.

                    Real programmers use butterflies

                    0 Offline
                    0 Offline
                    0x01AA
                    wrote on last edited by
                    #10

                    I agree. But a logging tool which becomes vulnerable by the data it should log is something idiotic, at least for me :-D

                    H 1 Reply Last reply
                    0
                    • 0 0x01AA

                      I agree. But a logging tool which becomes vulnerable by the data it should log is something idiotic, at least for me :-D

                      H Offline
                      H Offline
                      honey the codewitch
                      wrote on last edited by
                      #11

                      Well, in their defense, because of the string, date and file manipulation there are plenty of potential opportunities to exploit a library like that.

                      Real programmers use butterflies

                      1 Reply Last reply
                      0
                      • P Peter_in_2780

                        When I heard about it a bit over a week ago, I scanned all my file systems. The only bits that came close were some historical backups of long-dead machines. The first attempted exploit in my server logs was at 2021-12-11 00:28Z. Since then the "villains" are using all sorts of cute encoding tricks to get jndi past dumb filters that look for it in plain text. They account for currently around 7 or 8% of the noise traffic (i.e. by IP address, not hostname). And yes, I think there is a considerable "beatup" component. Apart from Minecraft, I haven't heard of any significant exploits.

                        Software rusts. Simon Stephenson, ca 1994. So does this signature. me, 2012

                        J Offline
                        J Offline
                        Jo_vb net
                        wrote on last edited by
                        #12

                        There is a fix available now? Upgraded to log4j 2.16? Surprise, there's a 2.17 fixing DoS[^]

                        1 Reply Last reply
                        0
                        • abmvA abmv

                          Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

                          Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

                          T Offline
                          T Offline
                          theoldfool
                          wrote on last edited by
                          #13

                          They are poking and probing: https://lous-stuff.com[^] #4 the other day.:mad:

                          >64 If you can keep your head while those about you are losing theirs, perhaps you don't understand the situation.

                          1 Reply Last reply
                          0
                          • abmvA abmv

                            Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

                            Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

                            P Offline
                            P Offline
                            PIEBALDconsult
                            wrote on last edited by
                            #14

                            Apparently Ab Initio uses it.

                            1 Reply Last reply
                            0
                            • R realJSOP

                              Another reason not to blindly jump on any "new" framework, just because it's "new". BTW, my team is full of programming gods, and we don't do logging. At all.

                              ".45 ACP - because shooting twice is just silly" - JSOP, 2010
                              -----
                              You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
                              -----
                              When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

                              D Offline
                              D Offline
                              dandy72
                              wrote on last edited by
                              #15

                              Programming gods wouldn't use a third-party logging library anyway; if needed, they'd roll their own.

                              1 Reply Last reply
                              0
                              • abmvA abmv

                                Does anyone actually use Log4J ? I means its like 1999...stuff ? ... I thought there were other diagnotsic api and services... the so called article writers who get paid to write doom to pay their rent...say that "The Log4J Vulnerability Will Haunt the Internet for Years"...........Its like replace "The covid pandemic Will Haunt the world for Years'......damn...

                                Caveat Emptor. "Progress doesn't come from early risers – progress is made by lazy men looking for easier ways to do things." Lazarus Long

                                O Offline
                                O Offline
                                obermd
                                wrote on last edited by
                                #16

                                There are tons of legacy systems built on old open source libraries. This is one of them. The problem I see coming is now that two of the major open source libraries have been found to be vulnerable (OpenSSL was the other one) cyber criminals and their government employed counterparts will start scanning older open source code for more vulnerabilities. Far too many entities never update their systems, especially when they're running open source systems that tend to be harder to update.

                                1 Reply Last reply
                                0
                                • H honey the codewitch

                                  Any library can become vulnerable if it doesn't bounds check everything. Back when I was a youth - and I don't recommend this - I rooted a server using their print daemon. It *is* weird that it's happening with the JVM, given java code is managed and thus relatively hardened, but I don't know *anything* about the exploit so I can only speak about exploits in general.

                                  Real programmers use butterflies

                                  J Offline
                                  J Offline
                                  jan larsen
                                  wrote on last edited by
                                  #17

                                  I heard it was an exploit in native code. A perfect example on why you should avoid native libraries.

                                  "God doesn't play dice" - Albert Einstein "God not only plays dice, He sometimes throws the dices where they cannot be seen" - Niels Bohr

                                  H 1 Reply Last reply
                                  0
                                  • J jan larsen

                                    I heard it was an exploit in native code. A perfect example on why you should avoid native libraries.

                                    "God doesn't play dice" - Albert Einstein "God not only plays dice, He sometimes throws the dices where they cannot be seen" - Niels Bohr

                                    H Offline
                                    H Offline
                                    honey the codewitch
                                    wrote on last edited by
                                    #18

                                    Ah, that makes sense.

                                    Real programmers use butterflies

                                    1 Reply Last reply
                                    0
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Don't have an account? Register

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • World
                                    • Users
                                    • Groups