After multiple patch releases, the Log4j vulnerability is still here, and doesn't appear to going away anytime soon. The latest patch is version 2.17.1, released Dec. 28, 2021.
Log4j added the ability to perform lookups: map lookups, system properties lookups as well as JNDI (Java Naming and Directory Interface) lookups. Log4j uses the JNDI API to obtain naming and directory services from several available service providers: LDAP (Lightweight Directory Access Protocol), COS (Common Object Services), Java RMI registry (Remote Method Invocation), DNS (Domain Name Service), etc.
This video demonstrates the latest Log4Shell vulnerability, steps to correct and the impact to the tech industry.
00:00 Introduction
00:41 Description and Demo of the threat
01:29 Mitigation
02:04 Industry reaction
02:40 U.S. Federal Trade Commission Response
03:28 Closing Remarks
Resources:
https://bit.ly/3ecIvsY
Support this channel by buying me a coffee:
https://www.buymeacoffee.com/EdClark
Смотрите видео Long Live Log4Shell | NEW Log4J Version 2.17.1 | Microsoft and FTC Response онлайн без регистрации, длительностью часов минут секунд в хорошем качестве. Это видео добавил пользователь Ed Clark 09 Январь 2022, не забудьте поделиться им ссылкой с друзьями и знакомыми, на нашем сайте его посмотрели 87 раз и оно понравилось 5 людям.