Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resource not found error #2

Open
Deathopex opened this issue Dec 15, 2021 · 1 comment
Open

Resource not found error #2

Deathopex opened this issue Dec 15, 2021 · 1 comment

Comments

@Deathopex
Copy link

Deathopex commented Dec 15, 2021

Recently my server got exploited, so I've decided to test if it's vulnerable by myself. But the remote code execution didn't work, the server throwed an error when object sent. I guess the exploit demo doesn't work properly.

11

@HyCraftHD
Copy link
Owner

Well alone the log tells you that you are vulnerable to CVE-2021-44228.
Your JDK seems to be JDK9+ so com.sun.jndi.ldap.object.trustURLCodebase is set the false by default. Did you enable that to test it?
I'll update the proof of concept to be a bit more robust and meaningful in the future.

Either way, you do not need to test the RCE to check if the exploit has been fixed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants