What do you need to know about the log4j (Log4Shell) vulnerability?

Поделиться
HTML-код
  • Опубликовано: 26 июл 2024
  • A Remote Code Execution (RCE) vulnerability in the popular log4j library was published yesterday.
    While any RCE vulnerability sounds bad, this one is particularly nasty because it affects absolutely any application (server and client-side) that uses a vulnerable version of the log4j library.
    In this live stream, we'll go over exploitation details and will see what blue teams can do to detect the attack and protect their environments.
    #cyber #cybersecurity #vulnerabilities #log4j #rce #remotecodeexecution #blueteaming #blueteam #blueteams #cyberattack
  • РазвлеченияРазвлечения

Комментарии • 31

  • @manmeetsnagi
    @manmeetsnagi 2 года назад +4

    This is great information, thank you so much.

  • @ssrinivas42
    @ssrinivas42 2 года назад +2

    Thanks for the information guys.

  • @JamesBrock72
    @JamesBrock72 2 года назад +2

    Great info, thanks for sharing.

  • @GuntisEiduks
    @GuntisEiduks 2 года назад +1

    Thank you for information.

  • @terrykirschner836
    @terrykirschner836 2 года назад

    Nice job Guys. Very useful information, and highly appreciated!!

  • @mikeboodry2391
    @mikeboodry2391 2 года назад +4

    This should have more views....

  • @Remador4ever
    @Remador4ever 2 года назад +1

    Thank you all!!

  • @remyadan2160
    @remyadan2160 2 года назад +1

    Great info

  • @generaldvw
    @generaldvw 2 года назад +1

    Good stuff.

  • @MartianMoon
    @MartianMoon 2 года назад +4

    Ok what is that banger song in the intro though?

  • @Synchrowize
    @Synchrowize 2 года назад +1

    Where can we find the slides please?

  • @afriend8961
    @afriend8961 2 года назад

    Attacker:
    We know you know this,
    You know we know your 'security'. =).

  • @calmeidazim
    @calmeidazim 2 года назад +8

    Thank you for this great webcast, any links for the slides and sites mention

  • @SteveWray
    @SteveWray 2 года назад +1

    Where does the IMMA model come from? It looks valuable but not finding many references.

    • @MichaelDouglas-ix1tt
      @MichaelDouglas-ix1tt 2 года назад +1

      I created it as a way to help my clients rapidly improve their security posture. This is the first time I've pushed it out to a broader audience.

    • @SteveWray
      @SteveWray 2 года назад +1

      ​@@MichaelDouglas-ix1tt The model makes a lot of sense. The way this log4j/jmdi issue is playing out, patching clearly won't be enough for some time to come. More basic security measures, which should always have been BAU, become more important than ever.
      Though, I particularly liked the addition of 'Active Defense' in the form of intrusion detection honeypots, something I've been promoting and researching myself, and which isn't widely used in the industry.

  • @pooley999
    @pooley999 2 года назад

    Thank. Do you recommend any honeypots?

    • @MichaelDouglas-ix1tt
      @MichaelDouglas-ix1tt 2 года назад

      because attackers are putting the Log4j string anywhere they can ANY web site honeypot that you like would work great. I strongly suggest using your own web apps as honeypots. Just look at the input logs.

  • @ezruy
    @ezruy 2 года назад +1

    0:04 Hello I'm ded

  • @evehong2944
    @evehong2944 2 года назад +1

    First guy gave extremely knowledgeable, practical, and actionable information. I'm not sure what the other two were doing.

    • @joe501ut
      @joe501ut 2 года назад +7

      all of them did a great job , their effort is much appreciated

    • @MichaelDouglas-ix1tt
      @MichaelDouglas-ix1tt 2 года назад +1

      Sorry you didn't like the info I gave. If you can give some constructive suggestions, I'm open. The defense against Log4j doesn't have to be that difficult. I was shooting for easy to do and quickly workable. Sorry if you felt it wasn't up to your expectations. Let me know what you think would be useful.

  • @JelMain
    @JelMain 2 года назад

    Please don't use the condescending "what you need to know about" format.

    • @MichaelDouglas-ix1tt
      @MichaelDouglas-ix1tt 2 года назад

      Sorry, we didn't mean to be condescending! Do you have a phrase that you feel is less loaded?