2021-045-Mick Douglas, Log4j vulnerabilities, egress mitigations- part1
2021-045-Mick Douglas, Log4j vulnerabilities, egress mitigations- part1

2021-045-Mick Douglas, Log4j vulnerabilities, egress mitigations- part1

Mrs_Marong💞

36 min
News
Play

Description

<p><span style="font-weight: 400;">Introduction</span></p> <p><span style="font-weight: 400;">Overview of Log4j vuln (as of 16 December 2021)</span></p> <p><span style="font-weight: 400;">Why is it a big deal? (impact/criticality/risk)</span></p> <p><span style="font-weight: 400;">Talk about patching vs. mitigation</span></p> <p><span style="font-weight: 400;">why wasn’t this given the same visibility in 2009? Because it’s Oracle or Java?</span></p> <p><span style="font-weight: 400;">Good callout is building slides to brief org leadership, detections, and other educational tools.</span></p> <p><span style="font-weight: 400;">Vuln fatigue (Java vulns in 2009 and pretty much forever cause us fatigue)</span></p> <p><span style="font-weight: 400;">Are there other technologies like log4j that prop up the entire world, and we just don’t know?</span></p> <p><span style="font-weight: 400;">Egress traffic (discussed at length on twitter, what problems it solve?)</span></p> <p><a href= "https://twitter.com/mubix/status/1470430085169745920"><span style= "font-weight: 400;">https://twitter.com/mubix/status/1470430085169745920</span></a></p> <p><span style="font-weight: 400;">Latest:</span> <a href= "https://www.theregister.com/2021/12/14/apache_log4j_v2_16_jndi_disabled_default/"> <span style= "font-weight: 400;">https://www.theregister.com/2021/12/14/apache_log4j_v2_16_jndi_disabled_default/</span></a> <span style="font-weight: 400;">- apache removed JDNI functionality</span></p> <p><a href= "https://www.reddit.com/r/blueteamsec/comments/rd38z9/log4j_0day_being_exploited/"> <span style= "font-weight: 400;">https://www.reddit.com/r/blueteamsec/comments/rd38z9/log4j_0day_being_exploited/</span></a> <span style="font-weight: 400;"><- great aggregation</span></p> <p><a href= "https://www.techsolvency.com/story-so-far/cve-2021-44228-log4j-log4shell/?fbclid=IwAR1ngTChJGz7Q5M-qbH6nwPBV4FByPDfJb98iLt_dbQO4EpZXVDwAxz0F8w"> <span style= "font-weight: 400;">https://www.techsolvency.com/story-so-far/cve-2021-44228-log4j-log4shell/</spa

Uploader

holly.cove

holly.cove

2021-045-Mick Douglas, Log4j vulnerabilities, egress mitigations- part1 - Listen Free | WowFM