video thumbnail 16:07
Log4j Lookups in Depth // Log4Shell CVE-2021-44228 - Part 2

2021-12-24

[public] 46.9K views, 3.28K likes, dislikes audio only

channel thumbLiveOverflow

In this video we dig a layer deeper into Log4j. We get a quick overview how Log4j is parsing lookup strings and find the functions used in WAF bypasses. Then we bridge the gap to format string vulnerabilities and figure out why the noLookups mitigation has flaws.

Part 1 - Hackers vs. Developers // CVE-2021-44228 Log4Shell: /youtube/video/w2F67LbEtnk

My lamest GitHub repo ever: https://github.com/LiveOverflow/log4shell

--

00:00 - Intro

00:38 - Chapter #1: Log4j Lookups in Depth Debugging

03:50 - Log Layout Formatters

06:56 - Chapter #2: Secure Software Design

09:21 - Chapter #3: Format String Vulnerabilities

13:58 - Chapter #4: noLookups Mitigation

15:15 - Final Worlds

15:42 - Outro

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Instagram: https://instagram.com/LiveOverflow/

→ Blog: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228 by LiveOverflow
/youtube/video/w2F67LbEtnk
Intro
/youtube/video/iI9Dz3zN4d8?t=0
Chapter #1: Log4j Lookups in Depth Debugging
/youtube/video/iI9Dz3zN4d8?t=38
Log Layout Formatters
/youtube/video/iI9Dz3zN4d8?t=230
Chapter #2: Secure Software Design
/youtube/video/iI9Dz3zN4d8?t=416
Chapter #3: Format String Vulnerabilities
/youtube/video/iI9Dz3zN4d8?t=561
Chapter #4: noLookups Mitigation
/youtube/video/iI9Dz3zN4d8?t=838
Final Worlds
/youtube/video/iI9Dz3zN4d8?t=915
Outro
/youtube/video/iI9Dz3zN4d8?t=942
I’m moving, no videos sorry 17,541 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
How SUDO on Linux was HACKED! // CVE-2021-3156 178,954 views
/youtube/video/TLa2VqcGGEQ