{"id":477869,"date":"2023-08-09T09:21:36","date_gmt":"2023-08-09T09:21:36","guid":{"rendered":""},"modified":"2023-09-05T11:15:35","modified_gmt":"2023-09-05T11:15:35","slug":"log4shell","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/cn\/wiki\/log4shell\/","title":{"rendered":"Log4Shell"},"content":{"rendered":"<p>Log4Shell \u662f\u4e00\u4e2a\u4e25\u91cd\u6f0f\u6d1e\uff0c\u4e8e 2021 \u5e74\u5e95\u51fa\u73b0\uff0c\u9707\u60ca\u4e86\u7f51\u7edc\u5b89\u5168\u9886\u57df\u3002\u5b83\u5229\u7528\u4e86\u5e7f\u6cdb\u4f7f\u7528\u7684\u65e5\u5fd7\u5e93 Apache Log4j \u4e2d\u7684\u4e00\u4e2a\u6f0f\u6d1e\uff0c\u5e76\u5141\u8bb8\u653b\u51fb\u8005\u5728\u6613\u53d7\u653b\u51fb\u7684\u7cfb\u7edf\u4e0a\u6267\u884c\u8fdc\u7a0b\u4ee3\u7801\u3002\u6b64\u6f0f\u6d1e\u7684\u4e25\u91cd\u6027\u4f7f\u5176\u83b7\u5f97\u4e86\u201c10.0\u201dCVSS\uff08\u901a\u7528\u6f0f\u6d1e\u8bc4\u5206\u7cfb\u7edf\uff09\u8bc4\u7ea7\uff0c\u8fd9\u662f\u6700\u9ad8\u5206\uff0c\u8868\u660e\u5b83\u6709\u53ef\u80fd\u9020\u6210\u5e7f\u6cdb\u800c\u6bc1\u706d\u6027\u7684\u7834\u574f\u3002<\/p>\n<h2>Log4Shell \u7684\u8d77\u6e90\u5386\u53f2\u4ee5\u53ca\u9996\u6b21\u63d0\u53ca\u5b83\u3002<\/h2>\n<p>Log4Shell \u7684\u8d77\u6e90\u53ef\u4ee5\u8ffd\u6eaf\u5230 Apache Log4j \u7684\u521b\u5efa\uff0cApache Log4j \u662f\u4e00\u4e2a\u6d41\u884c\u7684\u5f00\u6e90\u65e5\u5fd7\u8bb0\u5f55\u6846\u67b6\uff0c\u7528\u4e8e\u5404\u79cd\u57fa\u4e8e Java \u7684\u5e94\u7528\u7a0b\u5e8f\u30022021 \u5e74\u672b\uff0c\u5b89\u5168\u7814\u7a76\u4eba\u5458\u5728 Log4j \u4e2d\u53d1\u73b0\u4e86\u4e00\u4e2a\u4e25\u91cd\u6f0f\u6d1e\uff0c\u8be5\u6f0f\u6d1e\u5141\u8bb8\u653b\u51fb\u8005\u901a\u8fc7\u65e5\u5fd7\u8bb0\u5f55\u673a\u5236\u5c06\u6076\u610f\u4ee3\u7801\u6ce8\u5165\u7cfb\u7edf\u3002\u7b2c\u4e00\u6b21\u516c\u5f00\u63d0\u53ca Log4Shell \u662f\u5728\u5361\u5185\u57fa\u6885\u9686\u5927\u5b66\u7684 CERT \u534f\u8c03\u4e2d\u5fc3\u4e8e 2021 \u5e74 12 \u6708 9 \u65e5\u53d1\u5e03\u4e86\u4e00\u4efd\u6f0f\u6d1e\u8bf4\u660e (CVE-2021-44228)\u3002<\/p>\n<h2>\u6709\u5173 Log4Shell \u7684\u8be6\u7ec6\u4fe1\u606f\u3002\u6269\u5c55 Log4Shell \u4e3b\u9898\u3002<\/h2>\n<p>Log4Shell \u7684\u5f71\u54cd\u8303\u56f4\u8fdc\u8fdc\u8d85\u51fa\u4e86 Apache Log4j\uff0c\u56e0\u4e3a\u8bb8\u591a\u5e94\u7528\u7a0b\u5e8f\u548c\u4ea7\u54c1\u90fd\u96c6\u6210\u4e86\u8fd9\u4e2a\u5e93\uff0c\u56e0\u6b64\u5bb9\u6613\u53d7\u5230\u8be5\u6f0f\u6d1e\u7684\u5f71\u54cd\u3002\u8be5\u6f0f\u6d1e\u5b58\u5728\u4e8e Log4j \u5904\u7406\u5305\u542b\u7528\u6237\u63d0\u4f9b\u6570\u636e\u7684\u65e5\u5fd7\u6d88\u606f\u7684\u65b9\u5f0f\u4e2d\uff0c\u7279\u522b\u662f\u5728\u4f7f\u7528\u201c\u67e5\u627e\u201d\u529f\u80fd\u5f15\u7528\u73af\u5883\u53d8\u91cf\u65f6\u3002<\/p>\n<p>\u5f53\u6076\u610f\u884c\u4e3a\u8005\u901a\u8fc7\u64cd\u7eb5\u67e5\u627e\u7cbe\u5fc3\u5236\u4f5c\u65e5\u5fd7\u6d88\u606f\u65f6\uff0c\u5b83\u4f1a\u89e6\u53d1\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u3002\u8fd9\u6784\u6210\u4e86\u91cd\u5927\u5a01\u80c1\uff0c\u56e0\u4e3a\u653b\u51fb\u8005\u53ef\u4ee5\u5229\u7528 Log4Shell \u83b7\u5f97\u672a\u7ecf\u6388\u6743\u7684\u8bbf\u95ee\u3001\u7a83\u53d6\u654f\u611f\u6570\u636e\u3001\u7834\u574f\u670d\u52a1\uff0c\u751a\u81f3\u5b8c\u5168\u63a7\u5236\u76ee\u6807\u7cfb\u7edf\u3002<\/p>\n<h2>Log4Shell \u7684\u5185\u90e8\u7ed3\u6784\u3002Log4Shell \u7684\u5de5\u4f5c\u539f\u7406\u3002<\/h2>\n<p>Log4Shell \u901a\u8fc7\u5c06\u6613\u53d7\u653b\u51fb\u7684\u5e94\u7528\u7a0b\u5e8f\u6307\u5b9a\u4e3a\u73af\u5883\u53d8\u91cf\u7684\u67e5\u627e\u6e90\u6765\u5229\u7528 Log4j\u201c\u67e5\u627e\u201d\u673a\u5236\u3002\u5f53\u5e94\u7528\u7a0b\u5e8f\u6536\u5230\u6076\u610f\u65e5\u5fd7\u6d88\u606f\u65f6\uff0c\u5b83\u4f1a\u89e3\u6790\u5e76\u5c1d\u8bd5\u89e3\u6790\u5f15\u7528\u7684\u73af\u5883\u53d8\u91cf\uff0c\u4ece\u800c\u5728\u4e0d\u77e5\u60c5\u7684\u60c5\u51b5\u4e0b\u6267\u884c\u653b\u51fb\u8005\u7684\u4ee3\u7801\u3002<\/p>\n<p>\u4e3a\u4e86\u76f4\u89c2\u5730\u4e86\u89e3 Log4Shell \u7684\u8fdb\u7a0b\uff0c\u8bf7\u8003\u8651\u4ee5\u4e0b\u5e8f\u5217\uff1a<\/p>\n<ol>\n<li>\u653b\u51fb\u8005\u7cbe\u5fc3\u5236\u4f5c\u5305\u542b\u64cd\u7eb5\u7684\u67e5\u627e\u7684\u6076\u610f\u65e5\u5fd7\u6d88\u606f\u3002<\/li>\n<li>\u5b58\u5728\u6f0f\u6d1e\u7684\u5e94\u7528\u7a0b\u5e8f\u4f7f\u7528 Log4j \u8bb0\u5f55\u6d88\u606f\uff0c\u4ece\u800c\u89e6\u53d1\u67e5\u627e\u673a\u5236\u3002<\/li>\n<li>Log4j \u5c1d\u8bd5\u89e3\u51b3\u67e5\u627e\uff0c\u6267\u884c\u653b\u51fb\u8005\u7684\u4ee3\u7801\u3002<\/li>\n<li>\u53d1\u751f\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\uff0c\u6388\u4e88\u653b\u51fb\u8005\u672a\u7ecf\u6388\u6743\u7684\u8bbf\u95ee\u6743\u9650\u3002<\/li>\n<\/ol>\n<h2>Log4Shell \u7684\u5173\u952e\u7279\u6027\u5206\u6790\u3002<\/h2>\n<p>Log4Shell \u7684\u4e3b\u8981\u7279\u6027\u4f7f\u5f97\u5b83\u6210\u4e3a\u4e00\u4e2a\u6781\u5176\u5371\u9669\u7684\u6f0f\u6d1e\uff0c\u5305\u62ec\uff1a<\/p>\n<ol>\n<li><strong>CVSS \u8bc4\u5206\u9ad8<\/strong>\uff1aLog4Shell \u7684 CVSS \u8bc4\u5206\u4e3a 10.0\uff0c\u7a81\u663e\u4e86\u5176\u4e25\u91cd\u6027\u548c\u9020\u6210\u5e7f\u6cdb\u635f\u5bb3\u7684\u53ef\u80fd\u6027\u3002<\/li>\n<li><strong>\u5e7f\u6cdb\u5f71\u54cd<\/strong>\uff1a\u7531\u4e8e Apache Log4j \u7684\u6d41\u884c\uff0c\u5168\u7403\u6570\u767e\u4e07\u4e2a\u7cfb\u7edf\u53d8\u5f97\u8106\u5f31\uff0c\u5305\u62ec Web \u670d\u52a1\u5668\u3001\u4f01\u4e1a\u5e94\u7528\u7a0b\u5e8f\u3001\u4e91\u670d\u52a1\u7b49\u3002<\/li>\n<li><strong>\u5feb\u901f\u5229\u7528<\/strong>\uff1a\u7f51\u7edc\u72af\u7f6a\u5206\u5b50\u5f88\u5feb\u5c31\u9002\u5e94\u4e86\u5229\u7528\u8be5\u6f0f\u6d1e\u7684\u505a\u6cd5\uff0c\u56e0\u6b64\u5404\u7ec4\u7ec7\u5fc5\u987b\u7acb\u5373\u4fee\u8865\u5176\u7cfb\u7edf\u3002<\/li>\n<li><strong>\u8de8\u5e73\u53f0<\/strong>\uff1aLog4j \u662f\u8de8\u5e73\u53f0\u7684\uff0c\u8fd9\u610f\u5473\u7740\u8be5\u6f0f\u6d1e\u4f1a\u5f71\u54cd\u5404\u79cd\u64cd\u4f5c\u7cfb\u7edf\uff0c\u5305\u62ec Windows\u3001Linux \u548c macOS\u3002<\/li>\n<li><strong>\u5ef6\u8fdf\u4fee\u8865<\/strong>\uff1a\u4e00\u4e9b\u7ec4\u7ec7\u5728\u53ca\u65f6\u5e94\u7528\u8865\u4e01\u65b9\u9762\u9762\u4e34\u6311\u6218\uff0c\u5bfc\u81f4\u5176\u7cfb\u7edf\u957f\u671f\u66b4\u9732\u5728\u5916\u3002<\/li>\n<\/ol>\n<h2>Log4Shell \u7684\u7c7b\u578b<\/h2>\n<p>Log4Shell \u53ef\u4ee5\u6839\u636e\u5176\u5f71\u54cd\u7684\u5e94\u7528\u7a0b\u5e8f\u548c\u7cfb\u7edf\u7684\u7c7b\u578b\u8fdb\u884c\u5206\u7c7b\u3002\u4e3b\u8981\u7c7b\u578b\u5305\u62ec\uff1a<\/p>\n<table>\n<thead>\n<tr>\n<th>\u7c7b\u578b<\/th>\n<th>\u63cf\u8ff0<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u7f51\u7edc\u670d\u52a1\u5668<\/td>\n<td>\u5b58\u5728\u6f0f\u6d1e\u7684\u7f51\u7edc\u670d\u52a1\u5668\u66b4\u9732\u5728\u4e92\u8054\u7f51\u4e0a\uff0c\u5141\u8bb8\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u4f01\u4e1a\u5e94\u7528\u7a0b\u5e8f<\/td>\n<td>\u57fa\u4e8e Java \u7684\u4f01\u4e1a\u5e94\u7528\u7a0b\u5e8f\u4f7f\u7528 Log4j\uff0c\u5bb9\u6613\u53d7\u5230\u653b\u51fb\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u4e91\u670d\u52a1<\/td>\n<td>\u4f7f\u7528 Log4j \u8fd0\u884c Java \u5e94\u7528\u7a0b\u5e8f\u7684\u4e91\u5e73\u53f0\u4f7f\u5176\u9762\u4e34\u98ce\u9669\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u7269\u8054\u7f51\u8bbe\u5907<\/td>\n<td>\u7269\u8054\u7f51 (IoT) \u8bbe\u5907\u5229\u7528 Log4j\uff0c\u53ef\u80fd\u5bfc\u81f4\u8fdc\u7a0b\u653b\u51fb\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Log4Shell\u7684\u4f7f\u7528\u65b9\u6cd5\uff0c\u4f7f\u7528\u4e2d\u9047\u5230\u7684\u95ee\u9898\u4ee5\u53ca\u89e3\u51b3\u65b9\u6cd5\u3002<\/h2>\n<p><strong>\u4f7f\u7528 Log4Shell \u7684\u65b9\u6cd5\uff1a<\/strong><\/p>\n<ul>\n<li>\u5229\u7528\u66b4\u9732\u7684\u7f51\u7edc\u670d\u52a1\u5668\u6765\u7a83\u53d6\u654f\u611f\u6570\u636e\u6216\u5b89\u88c5\u6076\u610f\u8f6f\u4ef6\u3002<\/li>\n<li>\u901a\u8fc7\u6613\u53d7\u653b\u51fb\u7684\u4f01\u4e1a\u5e94\u7528\u7a0b\u5e8f\u4fb5\u5165\u4f01\u4e1a\u7f51\u7edc\u3002<\/li>\n<li>\u901a\u8fc7\u63a7\u5236\u4e91\u670d\u52a1\u53d1\u8d77 DDoS \u653b\u51fb\u3002<\/li>\n<li>\u5229\u7528\u7269\u8054\u7f51\u8bbe\u5907\u521b\u5efa\u50f5\u5c38\u7f51\u7edc\uff0c\u53d1\u52a8\u66f4\u5927\u89c4\u6a21\u653b\u51fb\u3002<\/li>\n<\/ul>\n<p><strong>\u95ee\u9898\u53ca\u89e3\u51b3\u65b9\u6848\uff1a<\/strong><\/p>\n<ul>\n<li>\u8865\u4e01\u5ef6\u8fdf\uff1a\u7531\u4e8e\u57fa\u7840\u8bbe\u65bd\u548c\u4f9d\u8d56\u5173\u7cfb\u590d\u6742\uff0c\u4e00\u4e9b\u7ec4\u7ec7\u96be\u4ee5\u53ca\u65f6\u5e94\u7528\u8865\u4e01\u3002\u89e3\u51b3\u65b9\u6848\u662f\u4f18\u5148\u8003\u8651\u8865\u4e01\u7ba1\u7406\uff0c\u5e76\u5c3d\u53ef\u80fd\u81ea\u52a8\u66f4\u65b0\u3002<\/li>\n<li>\u610f\u8bc6\u4e0d\u5b8c\u6574\uff1a\u5e76\u975e\u6240\u6709\u7ec4\u7ec7\u90fd\u610f\u8bc6\u5230\u4e86\u4ed6\u4eec\u7684 Log4j \u4f9d\u8d56\u5173\u7cfb\u3002\u5b9a\u671f\u5ba1\u8ba1\u548c\u5b89\u5168\u8bc4\u4f30\u53ef\u4ee5\u5e2e\u52a9\u8bc6\u522b\u6613\u53d7\u653b\u51fb\u7684\u7cfb\u7edf\u3002<\/li>\n<li>\u65e7\u7248\u5e94\u7528\u7a0b\u5e8f\uff1a\u65e7\u7248\u5e94\u7528\u7a0b\u5e8f\u53ef\u80fd\u5177\u6709\u8fc7\u65f6\u7684\u4f9d\u8d56\u9879\u3002\u7ec4\u7ec7\u5e94\u8003\u8651\u5347\u7ea7\u5230\u8f83\u65b0\u7248\u672c\u6216\u91c7\u7528\u53d8\u901a\u65b9\u6cd5\uff0c\u76f4\u5230\u53ef\u4ee5\u8fdb\u884c\u4fee\u8865\u3002<\/li>\n<\/ul>\n<h2>\u4ee5\u8868\u683c\u548c\u5217\u8868\u7684\u5f62\u5f0f\u5217\u51fa\u4e3b\u8981\u7279\u5f81\u4ee5\u53ca\u4e0e\u7c7b\u4f3c\u672f\u8bed\u7684\u5176\u4ed6\u6bd4\u8f83\u3002<\/h2>\n<p><strong>Log4Shell\u7684\u4e3b\u8981\u7279\u70b9\uff1a<\/strong><\/p>\n<ul>\n<li>\u6613\u53d7\u653b\u51fb\u7684\u8f6f\u4ef6\uff1aApache Log4j 2.x \u7248\u672c\uff08\u6700\u9ad8\u81f3 2.15.0\uff09\u53d7\u5230\u5f71\u54cd\u3002<\/li>\n<li>CVSS \u8bc4\u5206\uff1a10.0\uff08\u4e25\u91cd\uff09<\/li>\n<li>\u6f0f\u6d1e\u5229\u7528\u9014\u5f84\uff1a\u8fdc\u7a0b<\/li>\n<li>\u653b\u51fb\u590d\u6742\u5ea6\uff1a\u4f4e<\/li>\n<li>\u662f\u5426\u9700\u8981\u8eab\u4efd\u9a8c\u8bc1\uff1a\u5426<\/li>\n<\/ul>\n<p><strong>\u4e0e\u540c\u7c7b\u672f\u8bed\u7684\u6bd4\u8f83\uff1a<\/strong><\/p>\n<table>\n<thead>\n<tr>\n<th>\u6f0f\u6d1e<\/th>\n<th>CVSS \u8bc4\u5206<\/th>\n<th>\u5265\u524a\u5411\u91cf<\/th>\n<th>\u653b\u51fb\u590d\u6742\u6027<\/th>\n<th>\u9700\u8981\u8eab\u4efd\u9a8c\u8bc1<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Log4Shell<\/td>\n<td>10.0<\/td>\n<td>\u504f\u50fb\u7684<\/td>\n<td>\u4f4e\u7684<\/td>\n<td>\u4e0d<\/td>\n<\/tr>\n<tr>\n<td>\u5fc3\u8840<\/td>\n<td>9.4<\/td>\n<td>\u504f\u50fb\u7684<\/td>\n<td>\u4f4e\u7684<\/td>\n<td>\u4e0d<\/td>\n<\/tr>\n<tr>\n<td>\u70ae\u5f39\u4f11\u514b<\/td>\n<td>10.0<\/td>\n<td>\u504f\u50fb\u7684<\/td>\n<td>\u4f4e\u7684<\/td>\n<td>\u4e0d<\/td>\n<\/tr>\n<tr>\n<td>\u5e7d\u7075<\/td>\n<td>5.6<\/td>\n<td>\u672c\u5730\/\u8fdc\u7a0b<\/td>\n<td>\u4f4e\u7684<\/td>\n<td>\u4e0d<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u4e0e Log4Shell \u76f8\u5173\u7684\u672a\u6765\u89c2\u70b9\u548c\u6280\u672f\u3002<\/h2>\n<p>Log4Shell \u6f0f\u6d1e\u7ed9\u4e1a\u754c\u6572\u54cd\u4e86\u8b66\u949f\uff0c\u63d0\u9192\u4eba\u4eec\u8981\u4f18\u5148\u8003\u8651\u5b89\u5168\u6027\u548c\u8f6f\u4ef6\u4f9b\u5e94\u94fe\u5b8c\u6574\u6027\u3002\u56e0\u6b64\uff0c\u51fa\u73b0\u4e86\u591a\u79cd\u89c2\u70b9\u548c\u6280\u672f\u6765\u89e3\u51b3\u672a\u6765\u7c7b\u4f3c\u7684\u95ee\u9898\uff1a<\/p>\n<ol>\n<li><strong>\u589e\u5f3a\u8865\u4e01\u7ba1\u7406<\/strong>\uff1a\u7ec4\u7ec7\u6b63\u5728\u91c7\u7528\u81ea\u52a8\u8865\u4e01\u7ba1\u7406\u7cfb\u7edf\u6765\u786e\u4fdd\u53ca\u65f6\u66f4\u65b0\u5e76\u9632\u6b62\u50cf Log4Shell \u8fd9\u6837\u7684\u6f0f\u6d1e\u3002<\/li>\n<li><strong>\u5bb9\u5668\u5316\u548c\u5fae\u670d\u52a1<\/strong>\uff1aDocker \u548c Kubernetes \u7b49\u5bb9\u5668\u6280\u672f\u652f\u6301\u9694\u79bb\u7684\u5e94\u7528\u7a0b\u5e8f\u73af\u5883\uff0c\u4ece\u800c\u9650\u5236\u4e86\u6f0f\u6d1e\u7684\u5f71\u54cd\u3002<\/li>\n<li><strong>\u5b89\u5168\u5ba1\u8ba1\u4e0e\u8bc4\u4f30\u5de5\u5177<\/strong>\uff1a\u5148\u8fdb\u7684\u5b89\u5168\u5de5\u5177\u5bf9\u4e8e\u5ba1\u8ba1\u548c\u8bc4\u4f30\u8f6f\u4ef6\u4f9d\u8d56\u5173\u7cfb\u4ee5\u8bc6\u522b\u6f5c\u5728\u98ce\u9669\u53d8\u5f97\u81f3\u5173\u91cd\u8981\u3002<\/li>\n<li><strong>\u4e25\u683c\u7684\u5e93\u7248\u672c\u63a7\u5236<\/strong>\uff1a\u5f00\u53d1\u4eba\u5458\u5bf9\u5e93\u4f9d\u8d56\u6027\u66f4\u52a0\u8c28\u614e\uff0c\u53ea\u9009\u62e9\u7ef4\u62a4\u826f\u597d\u4e14\u6700\u65b0\u7684\u7248\u672c\u3002<\/li>\n<li><strong>\u5b89\u5168\u6f0f\u6d1e\u8d4f\u91d1\u8ba1\u5212<\/strong>\uff1a\u5404\u7ec4\u7ec7\u6b63\u5728\u6fc0\u52b1\u7f51\u7edc\u5b89\u5168\u7814\u7a76\u4eba\u5458\u8d1f\u8d23\u4efb\u5730\u53d1\u73b0\u548c\u62a5\u544a\u6f0f\u6d1e\uff0c\u4ee5\u4fbf\u5c3d\u65e9\u53d1\u73b0\u548c\u7f13\u89e3\u6f0f\u6d1e\u3002<\/li>\n<\/ol>\n<h2>\u5982\u4f55\u4f7f\u7528\u4ee3\u7406\u670d\u52a1\u5668\u6216\u5c06\u5176\u4e0e Log4Shell \u5173\u8054\u3002<\/h2>\n<p>\u4ee3\u7406\u670d\u52a1\u5668\u5728\u589e\u5f3a\u7f51\u7edc\u5b89\u5168\u65b9\u9762\u53d1\u6325\u7740\u81f3\u5173\u91cd\u8981\u7684\u4f5c\u7528\uff0c\u5b83\u5145\u5f53\u7740\u7528\u6237\u548c\u4e92\u8054\u7f51\u4e4b\u95f4\u7684\u4e2d\u4ecb\u3002\u867d\u7136\u4ee3\u7406\u670d\u52a1\u5668\u672c\u8eab\u4e0d\u4f1a\u76f4\u63a5\u53d7\u5230 Log4Shell \u7684\u653b\u51fb\uff0c\u4f46\u5b83\u4eec\u53ef\u4ee5\u95f4\u63a5\u5730\u5e2e\u52a9\u51cf\u8f7b\u4e0e\u8be5\u6f0f\u6d1e\u76f8\u5173\u7684\u98ce\u9669\u3002<\/p>\n<p><strong>\u4ee3\u7406\u670d\u52a1\u5668\u5728 Log4Shell \u7f13\u89e3\u4e2d\u7684\u4f5c\u7528\uff1a<\/strong><\/p>\n<ol>\n<li><strong>\u7f51\u9875\u8fc7\u6ee4<\/strong>\uff1a\u4ee3\u7406\u670d\u52a1\u5668\u53ef\u4ee5\u8fc7\u6ee4\u548c\u963b\u6b62\u6076\u610f\u6d41\u91cf\uff0c\u963b\u6b62\u653b\u51fb\u8005\u8bbf\u95ee\u6613\u53d7\u653b\u51fb\u7684\u7f51\u7edc\u670d\u52a1\u5668\u3002<\/li>\n<li><strong>\u5185\u5bb9\u68c0\u67e5<\/strong>\uff1a\u4ee3\u7406\u53ef\u4ee5\u68c0\u67e5\u4f20\u5165\u548c\u4f20\u51fa\u7684\u6d41\u91cf\u4e2d\u662f\u5426\u5b58\u5728\u6076\u610f\u8d1f\u8f7d\uff0c\u4ece\u800c\u963b\u6b62\u5c1d\u8bd5\u6027\u7684\u653b\u51fb\u3002<\/li>\n<li><strong>SSL \u68c0\u67e5<\/strong>\uff1a\u901a\u8fc7\u89e3\u5bc6\u548c\u68c0\u67e5 SSL\/TLS \u6d41\u91cf\uff0c\u4ee3\u7406\u53ef\u4ee5\u68c0\u6d4b\u5e76\u963b\u6b62\u9690\u85cf\u5728\u52a0\u5bc6\u8fde\u63a5\u4e2d\u7684\u6076\u610f\u4ee3\u7801\u3002<\/li>\n<li><strong>\u7f13\u5b58\u548c\u538b\u7f29<\/strong>\uff1a\u4ee3\u7406\u53ef\u4ee5\u7f13\u5b58\u7ecf\u5e38\u8bbf\u95ee\u7684\u8d44\u6e90\uff0c\u4ece\u800c\u51cf\u5c11\u901a\u8fc7\u6613\u53d7\u653b\u51fb\u7684\u5e94\u7528\u7a0b\u5e8f\u7684\u8bf7\u6c42\u6570\u91cf\u3002<\/li>\n<\/ol>\n<p>\u50cf OneProxy \u8fd9\u6837\u7684\u4ee3\u7406\u670d\u52a1\u5668\u63d0\u4f9b\u5546\u53ef\u4ee5\u5c06 Log4Shell \u7279\u5b9a\u7684\u5b89\u5168\u63aa\u65bd\u96c6\u6210\u5230\u4ed6\u4eec\u7684\u4ea7\u54c1\u4e2d\uff0c\u4ece\u800c\u589e\u5f3a\u5176\u5ba2\u6237\u5bf9\u65b0\u51fa\u73b0\u7684\u6f0f\u6d1e\u7684\u6574\u4f53\u9632\u62a4\u3002<\/p>\n<h2>\u76f8\u5173\u94fe\u63a5<\/h2>\n<p>\u6709\u5173 Log4Shell \u4ee5\u53ca\u5982\u4f55\u4fdd\u62a4\u7cfb\u7edf\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u8bf7\u53c2\u9605\u4ee5\u4e0b\u8d44\u6e90\uff1a<\/p>\n<ol>\n<li><a href=\"https:\/\/logging.apache.org\/log4j\/2.x\/\" target=\"_new\" rel=\"noopener nofollow\">Apache Log4j \u5b98\u65b9\u7f51\u7ad9<\/a><\/li>\n<li><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-44228\" target=\"_new\" rel=\"noopener nofollow\">NIST \u56fd\u5bb6\u6f0f\u6d1e\u6570\u636e\u5e93 (NVD) \u2013 CVE-2021-44228<\/a><\/li>\n<li><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa21-339a\" target=\"_new\" rel=\"noopener nofollow\">CISA \u2013 \u8b66\u62a5 (AA21-339A) \u2013 \u653e\u5927\u88ab\u76d7\u51ed\u8bc1<\/a><\/li>\n<\/ol>\n<p>\u968f\u65f6\u4e86\u89e3\u5e76\u4fdd\u62a4\u60a8\u7684\u7cfb\u7edf\u514d\u53d7 Log4Shell \u7684\u6f5c\u5728\u5a01\u80c1\u3002<\/p>","protected":false},"featured_media":0,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-477869","wiki","type-wiki","status-publish","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Log4Shell: Unraveling the Complexities of a Critical Vulnerability<\/mark>","faq_items":[{"question":"What is Log4Shell?","answer":"<p>Log4Shell is a critical vulnerability that emerged in late 2021. It exploits a flaw in the widely used logging library, Apache Log4j, allowing attackers to execute remote code on vulnerable systems.<\/p>"},{"question":"How did Log4Shell originate?","answer":"<p>The vulnerability originated in the Apache Log4j logging framework. It was first publicly mentioned by the CERT Coordination Center at Carnegie Mellon University on December 9, 2021.<\/p>"},{"question":"How does Log4Shell work?","answer":"<p>Log4Shell manipulates the Log4j \"lookup\" feature, injecting malicious code into vulnerable systems through specially crafted log messages. When the application processes these logs, the attacker's code executes, granting unauthorized access.<\/p>"},{"question":"What are the key features of Log4Shell?","answer":"<p>Log4Shell's criticality is highlighted by its CVSS score of 10.0. It impacts millions of systems, including web servers, enterprise apps, and cloud services. Attackers can exploit it to gain control, steal data, and disrupt services.<\/p>"},{"question":"What types of Log4Shell exist?","answer":"<p>Log4Shell can impact web servers, enterprise apps, cloud services, and IoT devices.<\/p>"},{"question":"How can Log4Shell be used, and what are the solutions to related problems?","answer":"<p>Log4Shell can be used to compromise web servers, breach corporate networks, launch DDoS attacks, and create IoT botnets. Solutions include prioritizing patch management, conducting regular security audits, and upgrading legacy applications.<\/p>"},{"question":"What are the main characteristics of Log4Shell, and how does it compare to similar terms?","answer":"<p>Log4Shell is characterized by its high CVSS score, remote exploitation vector, low attack complexity, and no authentication required. It is more critical than terms like Heartbleed, Shellshock, and Spectre.<\/p>"},{"question":"What are the future perspectives and technologies related to Log4Shell?","answer":"<p>The industry emphasizes enhanced patch management, containerization, security auditing tools, library version control, and bug bounty programs to mitigate future vulnerabilities.<\/p>"},{"question":"How can proxy servers be associated with Log4Shell?","answer":"<p>Proxy servers indirectly contribute to Log4Shell mitigation by filtering malicious traffic, inspecting content, decrypting SSL traffic, caching resources, and compressing data.<\/p>"},{"question":"Where can I find more information about Log4Shell?","answer":"<p>For more information, visit the official Apache Log4j website, the NIST National Vulnerability Database (CVE-2021-44228), and CISA's Alert (AA21-339A) on Amplified Stolen Credentials. Stay informed and safeguard your systems against Log4Shell's threats.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki\/477869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/wiki\/477869\/revisions"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/cn\/wp-json\/wp\/v2\/media?parent=477869"}],"curies":[{"name":"\u53ef\u6e7f\u6027\u7c89\u5242","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}