Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
Log4j zero day just dropped

https://twitter.com/campuscodi/status/1469276512847339521?s=20

Adbot
ADBOT LOVES YOU

some kinda jackal
Feb 25, 2003

 
 
Just in time for everyone to have to justify an emergency patch during their company's holiday code/production change/etc freeze period.

:thumbsup:

Saukkis
May 16, 2003

Unless I'm on the inside curve pointing straight at oncoming traffic the high beams stay on and I laugh at your puny protest flashes.
I am Most Important Man. Most Important Man in the World.
We have also been dealing with this at work. Coworker has been testing servers with this python script, but hasn't gotten a hit yet.
https://gist.github.com/byt3bl33d3r/46661bc206d323e6770907d259e009b6

Either the servers are using Log4j 1.x, or they are using OpenJDK from RHEL or Ubuntu which have partially mitigated this years ago with CVE-2018-3149.

some kinda jackal
Feb 25, 2003

 
 
imagine having a job where you aren't terrified of looking at your news feed to see what fresh hell awaits you

Saukkis
May 16, 2003

Unless I'm on the inside curve pointing straight at oncoming traffic the high beams stay on and I laugh at your puny protest flashes.
I am Most Important Man. Most Important Man in the World.
There's now speculation that Log4j 1.x is also vulnerable. And it's of course also EOL'd and won't receive updates.
https://github.com/apache/logging-log4j2/pull/608#issuecomment-990494126

some kinda jackal
Feb 25, 2003

 
 
As a really simple customer-facing mitigation, is payload inspection at a WAF a possible emergency workaround If the concern is arbitrary user input focusing on jndi or am I really naive here. Not enough caffeine and I'm still waking up.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Martytoof posted:

As a really simple customer-facing mitigation, is payload inspection at a WAF a possible emergency workaround If the concern is arbitrary user input focusing on jndi or am I really naive here. Not enough caffeine and I'm still waking up.

Cloudflare has released some stuff as a workaround in, so yes. Also there's mitigation such as adding a java runtime argument that helps prevent it

https://twitter.com/_JohnHammond/status/1469255402290401285?s=20

https://blog.cloudflare.com/cve-2021-44228-log4j-rce-0-day-mitigation/

If you are running anything Java like Minecraft, add this to your Java args until you can update/patch: +log4j2.formatmsgnolookups=true

CommieGIR fucked around with this message at 15:03 on Dec 10, 2021

Proteus Jones
Feb 28, 2013



CommieGIR posted:

If you are running anything Java like Minecraft, add this to your Java args until you can update/patch: +log4j2.formatmsgnolookups=true

According to the article, that's all the latest patch does anyway.

quote:

According to p0rz9, the Chinese security researcher who first posted the exploit code online, CVE-2021-44228 can only be abused if the log4j2.formatMsgNoLookups option in the library’s configuration is set to false.

In a conversation today, Heige, the founder and CEO of Chinese security firm KnownSec 404 Team and one of the first researchers to understand the vulnerability’s impact, told The Record that today’s Log4j 2.15.0 release basically sets this option to true in order to block attacks.

Log4j users who update to the 2.15.0 version but then set this flag back to false will remain vulnerable to attacks. Similarly, Log4j users who can’t update but set the flag to true can block attacks even on older versions.

Unfortunately, this option is set to false by default in old releases, meaning that all past Log4j releases since 2.10.0, when this option was added, are vulnerable by default.

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Proteus Jones posted:

According to the article, that's all the latest patch does anyway.

Lol, gotta love simple fixes

Nukelear v.2
Jun 25, 2004
My optional title text

Proteus Jones posted:

According to the article, that's all the latest patch does anyway.

The diff looks to be a might more thorough than just that https://issues.apache.org/jira/browse/LOG4J2-3201, looks like you'd have to change quite a few settings.

FungiCap
Jul 23, 2007

Let's all just calm down and put on our thinking caps.
Already seeing active attempts at exploitation and had to patch at least 1 public facing device. Always on a Friday or a holiday.

RFC2324
Jun 7, 2012

http 418

We still aren't done patching the last CVE :negative:

Fart Amplifier
Apr 12, 2003

Well well well, if it isn't the consequences of our own actions.

Sure glad we have no real way to monitor for this vulnerability.

some kinda jackal
Feb 25, 2003

 
 
Just enable more logg-ohhhhh

Tryzzub
Jan 1, 2007

Mudslide Experiment
my thread title still stands

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


I'm so tired

BlankSystemDaemon
Mar 13, 2009



It's okay to find other employment when you get exhausted, friend.

repiv
Aug 13, 2009

https://twitter.com/brianloveswords/status/1469358777409454092

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


FYI Panorama actually uses log4j, but firewall PAN-OS does not - https://docs.paloaltonetworks.com/oss-listings/panorama-oss-listings/panorama-9-1-open-source-software-oss-listing.html https://docs.paloaltonetworks.com/oss-listings/pan-os-oss-listings/pan-os-9-1-open-source-software-oss-listing.html. PAN just released a security advisory that they're investigating whether or not Panorama is affected https://security.paloaltonetworks.com/CVE-2021-44228

some kinda jackal
Feb 25, 2003

 
 
How many shops are having this conversation right now:


"Can anyone tell me how vulnerable we are to log4j? -> can anyone tell me how many apps run on java? -> can anyone tell me how many servers we have???"

Sickening
Jul 16, 2007

Black summer was the best summer.

Martytoof posted:

How many shops are having this conversation right now:


"Can anyone tell me how vulnerable we are to log4j? -> can anyone tell me how many apps run on java? -> can anyone tell me how many servers we have???"

I feel like the jump from a->b is taking a lot longer than people are willing to talk about.

Mustache Ride
Sep 11, 2001



Elastic and logstash: https://github.com/elastic/elasticsearch/issues/81618#issuecomment-991000240

Nukelear v.2
Jun 25, 2004
My optional title text

Meanwhile Prisma Cloud Compute (Twistlock) still can't track this CVE, would have been real easy to figure out our exposure if this was working.

some kinda jackal
Feb 25, 2003

 
 
I'm imagining two or more APTs fighting for dominance inside a clueless organization for the next 6 months and it's pretty much the only thing making me smile right now.

Fart Amplifier
Apr 12, 2003

One of our team members found out that running curl against our Powerschool SIS servers, intentionally generating a 404, and setting the jdni string in the response header triggered our canary token. So yeah, our division took the SIS off the internet and we're awaiting Powerschool's response.

Absurd Alhazred
Mar 27, 2010

by Athanatos
Should I care if I don't run any Java?

Tryzzub
Jan 1, 2007

Mudslide Experiment
You may have vendors who do, so generally yes

Absurd Alhazred
Mar 27, 2010

by Athanatos
I don't mean like should my company care, but is there something I personally should be doing differently, at home, as someone who isn't running Java.

some kinda jackal
Feb 25, 2003

 
 
(IMO) You, personally, are a minor target at best. Unless your neighbour really hates you and wants to gently caress with your WiFi by doing the device-name-RCE thing you are probably fine. Stay up to date on vendor patches for your internet connected garbage. If you run a DMZ network on your home LAN then understand what you are exposing and make sure it's patched.

Maybe more serious if you have an Android phone I suppose?

Fart Amplifier
Apr 12, 2003

Absurd Alhazred posted:

I don't mean like should my company care, but is there something I personally should be doing differently, at home, as someone who isn't running Java.

Honest question, how do you know you're not running Java?

Tryzzub
Jan 1, 2007

Mudslide Experiment
If you have anything public facing/accessible it doesn’t hurt to check product pages for patches.

I’ve been seeing opportunistic scanning/attempts all day to anything with an ipv4 address, not unlike the exchange stuff earlier in the year.

log4j is ubiquitous and the exploit is trivial

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug
So minor update: If you are less than version 2.10 of Log4j the Java Exec mitigation won't work. You gotta patch. Found that out in a VM today

And VMWare was affected by this

https://www.vmware.com/security/advisories/VMSA-2021-0028.html?cid=70134000001YTvO&src=so_5b27ee4a667bd

Absurd Alhazred
Mar 27, 2010

by Athanatos

Martytoof posted:

Maybe more serious if you have an Android phone I suppose?

Oh, dear, yeah, I do have an Android, I hadn't even thought of that.

Fart Amplifier posted:

Honest question, how do you know you're not running Java?

Aside from the Android I forgot had Java in it, I never installed Java on this computer.

some kinda jackal
Feb 25, 2003

 
 
I mean I'm not saying there's anything identified that is going on with Android right this second, just in my mind a phone that basically runs Java and interacts with the world is probably something to keep an eye on right now.

Fart Amplifier
Apr 12, 2003

Absurd Alhazred posted:

Aside from the Android I forgot had Java in it, I never installed Java on this computer.

And you're sure you haven't installed anything that bundles it?

Absurd Alhazred
Mar 27, 2010

by Athanatos

Fart Amplifier posted:

And you're sure you haven't installed anything that bundles it?

I'm pretty sure? How would I check?

some kinda jackal
Feb 25, 2003

 
 

Absurd Alhazred posted:

I'm pretty sure? How would I check?

- Every company's infrastructure team with hands on servers on December 10 2021

Absurd Alhazred
Mar 27, 2010

by Athanatos

Martytoof posted:

- Every company's infrastructure team with hands on servers on December 10 2021

I mean, I looked at Add/Remove programs, I've searched my disk, I don't have java or jre anywhere. Am I missing something?

some kinda jackal
Feb 25, 2003

 
 
No, i'm being sarcastic. Sorry it's been a long long day.

Adbot
ADBOT LOVES YOU

Absurd Alhazred
Mar 27, 2010

by Athanatos
No worries, and I imagine!

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply