A vulnerability in the widely used Apache Log4j for the Java software platform has compromised the security of numerous Internet services and applications, and attackers are already trying to exploit it. about this . writes Wired
The essence of the vulnerability is briefly this: if you somehow force Log4J to write a line with a specific command to the application event log, this will allow the attacker to remotely run any code he needs, including malicious ones. The vulnerability has been coded CVE-2021-44228.
Java is not as popular among modern developers, but a significant portion of enterprise software and web applications use it. were at risk . Thus, the Apache Tomcat web server, used by the trading giant Alibaba, full-text search system the Elasticsearch used by Wikimedia and Github, as well as popular development management tools Jira and Confluence,
Wired gives examples of exploitation of the vulnerability: users send the desired command to the chat of the popular game Minecraft or change the names of iPhones to force Apple to register it.
“We have concluded that the vulnerability in Log4J is so dangerous that we will try to implement at least some protection for all users by default, even for free customers,” writes provider Matthew Prince, founder of DNS service Cloudflare . “This is a serious vulnerability that is already being actively exploited.”
The computer rapid response team (CERT) of the German Deutsche Telekom already on December 10 recorded large-scale attempts to exploit the vulnerability emanating from Tor networks. At the same time, cybersecurity experts discussing are also the threat to hidden servers of Tor itself , whose IP addresses may become visible due to vulnerability.