CISA’s Scanner Identifies Web Services Impacted By Log4J Flaw

Share post:

The Cybersecurity and Infrastructure Security Agency (CISA) introduced the Log4J scanner, which will help identify web services affected by two Log4j flaws (CVE-2021-44228 and CVE-2021-45046).

The tool, based on an automated scanning framework developed by cybersecurity firm FullHunt, allows security teams to scan network hosts for two main actions, including Log4j RCE exposure and detection of web application firewall (WAF) bypasses that can allow attackers to execute code within an organization’s network.

Notable features of the Log4j scanner include support for lists of URLs, fuzzing for more than 60 HTTP request headers, fuzzing for HTTP Post Data parameters, fuzzing for JSON data parameters, DNS callback support for vulnerability discovery and validation, and WAF Bypass payloads.

These and many more are some of the efforts of CISA to mitigate attacks resulting from the successful exploitation of the Log4j flaw.

For more information, read the original story in BleepingComputer.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Developer of “Unfollow Everything” sues Meta over control of social feeds

Ethan Zuckerman, an associate professor at the University of Massachusetts—Amherst, has filed a lawsuit against Meta, arguing that...

New York business leaders most optimistic about impact of AI: Accenture study

New York City's business elite are increasingly optimistic about the transformative potential of artificial intelligence, according to a...

Intel’s foundry business suffers $7 billion loss in 2023 amidst ambitious expansion

Intel's expansion into the foundry business as part of its IDM 2.0 strategy has resulted in a staggering...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways