The Log4j Vulnerability: Patching and Mitigation

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 ธ.ค. 2024

ความคิดเห็น • 19

  • @samirshaikh6494
    @samirshaikh6494 3 ปีที่แล้ว

    Thank you Motasem making informative video. This channel is so much underrated. Needs more subscribers and viewers.

  • @drakezen
    @drakezen 3 ปีที่แล้ว

    My understanding is that the version 2.16 is not sufficient as a solution as it allows for denial of service attacks, so 2.17 is the current recommendation. This video is very well explained and helpful, thanks!

    • @MotasemHamdan
      @MotasemHamdan  3 ปีที่แล้ว +1

      Yes exactly that was after I published the video :)

    • @drakezen
      @drakezen 3 ปีที่แล้ว

      @@MotasemHamdan and after I wrote that I heard that 2.17 has issues too. We have to wait for 2.18 !

  • @louis417asdo
    @louis417asdo 2 ปีที่แล้ว

    ​ Hi I am new in here, I have read your comment below but don't understand, what do you mean no delete but just copy and replace?
    Say currently the application is using 2.14 core, and I copy the 2.17.1 core in the same folder, but don't delete the 2.14 core and keep it there?? And any configure do we need to adjust after replace the .jar files?

    • @MotasemHamdan
      @MotasemHamdan  2 ปีที่แล้ว

      Just replace old files with new ones :)

  • @jayrawani
    @jayrawani 2 ปีที่แล้ว

    Hi, can u plz provide note on updating from 2.11.1 to 2.17.0 log4j for Linux elasticsearch

  • @private9281
    @private9281 3 ปีที่แล้ว

    How to replace those files with new file if we have downloaded on same server
    Can we do it at once

    • @MotasemHamdan
      @MotasemHamdan  3 ปีที่แล้ว +2

      You can use 'cp' to achieve this purpose. Say you want to replace old 'jar' with new ones you can use the below command
      cp /directory/*jar /old-jar/*.jar

    • @networktopics4630
      @networktopics4630 3 ปีที่แล้ว

      @@MotasemHamdan should I delete old files afterwards? or will they be disabled ?

    • @MotasemHamdan
      @MotasemHamdan  3 ปีที่แล้ว +1

      @@networktopics4630 No to delete just copy and replace.

    • @louis417asdo
      @louis417asdo 2 ปีที่แล้ว

      ​@@MotasemHamdan Hi I am new in here, I don't understand, what do you mean no delete but just copy and replace?
      Say currently the application is using 2.14 core, and I copy the 2.17.1 core in the same folder, but don't delete the 2.14 core and keep it there?? And any configure do we need to adjust after replace the .jar files?

  • @UmairAli
    @UmairAli 3 ปีที่แล้ว

    Thank for uploading this , really informative , just one question , I am very much curious and interested to know more about this I mean , If there's a Possibility that you could guide me where I could get the code of a web application that uses log4j's vulnerable version and patched one , it would be great cuz as a developer and pentester I would really wanna inspect if for understanding purposes .. and thanks again ,

    • @MotasemHamdan
      @MotasemHamdan  3 ปีที่แล้ว +1

      Take Apache struct and install log4j prior to 2.16.0.
      Patched version is 2.16.0

    • @UmairAli
      @UmairAli 3 ปีที่แล้ว

      @@MotasemHamdan Thanks ♥

  • @ramenpradhan2836
    @ramenpradhan2836 3 ปีที่แล้ว

    Can you please provide the notes or please tell me how to get the notes

    • @MotasemHamdan
      @MotasemHamdan  3 ปีที่แล้ว

      Hello Ramen, Notes are part of channel membership
      th-cam.com/channels/NSdU_1ehXtGclimTVckHmQ.htmljoin

  • @jvr8360
    @jvr8360 3 ปีที่แล้ว

    thnx

  • @scramble111
    @scramble111 ปีที่แล้ว

    terrible