Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-44228 PoC — Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

Source
Associated Vulnerability
Title:Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints (CVE-2021-44228)
Description:Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Description
Log4j Vulnerability Scanner
Readme
-My intention was to concieve of a novel, and effective, policy-based data science framework to optimize a massively distributed alternative 
data landscape. By leveraging emerging critical new technological advances in operations and core processes, integrated natively, in an
architecture which bridges the gap between classical AI responsiveness and theory of mind machine cognition capabilities, thus allowing for 
the formulation of an enhanced understanding of people and things, and, of feelings and behaviours, all of which are processed within a 
Engineered Virtual Enviroment (EvE) and represented by a Digital Voice Persona (DVP).
     The EvE-DVP ecosystem sorts human emotions, sentiments, and thoughts, based on self-learned metrics (SLM) and user interactions, very 
     similar to KISMET's ability to mimic human emotions, the EvE-DVP discovers patterns, similarities, and relationships, as well as the
     autonomous recognition of indicators with potential emotional significance which are compiled into usefull dynamic profiles, which form
     the basis for comparisson analysis, optimized for Positive Content Generation (PCG) that satisfies core desires of human relational,
     personality, and expression, and measures levels of content and satisfaction, which generates insight into increasing the wellbeing of
     the user, and tailor-made content delivery to modulate opinion, emotion, and engagement.
        The EvE-DVP is a Conceptual Awareness Generator (CAG), technically speaking, a limited-memory, reactive and Deep Learning (DL) 
        modelled hybrid machine which exploits the opportunities of Artificial Narrow Intelligence (ANI) technology, combining General 
        Intelligence (GI) that applies knowledge and special skills, in different contexts, with autonomous learning and problem solving capabilities
        that utilizes enhanced memory, faster data processing, analysis, and decision-making, that is augmented by a novel Deep Learning (DL)
        element of the Machine Learning (ML) subsystem within the Artificial Intelligence (AI) system.
           The EvE-DVP is a full-scope control plane across the multi-domain ecosystem, using a technological capability and structural
           maturity methodology which enhances the detection of cognative elements that comprehends, learns, stores and represents knowledge,
           reason and communications interactions with humans. 
            l

<!---
marklindsey11/marklindsey11 is a ✨ special ✨ repository because its `README.md` (this file) appears on your GitHub profile.
You can click the Preview link to take a look at your changes.
--->
File Snapshot

[4.0K] /data/pocs/e8cf5850004e44b0e2f35d226f7e90fcaa054da8 ├── [ 22] CNAME └── [2.6K] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →