After multiple patch releases, the Log4j vulnerability is still here, and doesn't appear to going away anytime soon. The latest patch is version 2.17.1, released Dec. 28, 2021.
Log4j added the ability to perform lookups: map lookups, system properties lookups as well as JNDI (Java Naming and Directory Interface) lookups. Log4j uses the JNDI API to obtain naming and directory services from several available service providers: LDAP (Lightweight Directory Access Protocol), COS (Common Object Services), Java RMI registry (Remote Method Invocation), DNS (Domain Name Service), etc.
This video demonstrates the latest Log4Shell vulnerability, steps to correct and the impact to the tech industry.
00:00 Introduction
00:41 Description and Demo of the threat
01:29 Mitigation
02:04 Industry reaction
02:40 U.S. Federal Trade Commission Response
03:28 Closing Remarks
Resources:
https://bit.ly/3ecIvsY
Support this channel by buying me a coffee:
https://www.buymeacoffee.com/EdClark
Watch video Long Live Log4Shell | NEW Log4J Version 2.17.1 | Microsoft and FTC Response online without registration, duration hours minute second in high quality. This video was added by user Ed Clark 09 January 2022, don't forget to share it with your friends and acquaintances, it has been viewed on our site 87 once and liked it 5 people.