{"id":427942,"date":"2021-12-17T11:41:56","date_gmt":"2021-12-17T09:41:56","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=427942"},"modified":"2021-12-17T11:42:30","modified_gmt":"2021-12-17T09:42:30","slug":"fix-for-log4j-exploit-has-its-own-vulnerabilities","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/427942-fix-for-log4j-exploit-has-its-own-vulnerabilities.html","title":{"rendered":"Fix for Log4J exploit has its own vulnerabilities"},"content":{"rendered":"<p>Open-source developers released a patch for a severe vulnerability in Apache&#8217;s Log4J, and the fix has been discovered to have two vulnerabilities of its own.<\/p>\n<p>According to a <strong><a href=\"https:\/\/arstechnica.com\/information-technology\/2021\/12\/patch-fixing-critical-log4j-0-day-has-its-own-vulnerability-thats-under-exploit\/\" target=\"_blank\" rel=\"noopener\">report<\/a><\/strong> from Ars Technica, the fix allowed attackers to execute denial-of-service attacks, making it easy to take vulnerable services offline until they reboot their servers.<\/p>\n<p>Researchers are encouraging users to update to a new patch \u2014 2.16.0 \u2014 as a potential fix for the vulnerability.<\/p>\n<p>They said that the initial fix &#8220;was incomplete in certain non-default configurations&#8221; and that the new patch &#8220;fixes this issue by removing support for message lookup patterns and disabling JNDI functionality by default&#8221;.<\/p>\n<p>The zero-day exploit was <strong><a href=\"https:\/\/mybroadband.co.za\/news\/security\/427204-critical-security-flaw-being-exploited-all-over-the-internet.html\" target=\"_blank\" rel=\"noopener\">detected<\/a><\/strong> on 9 December 2021 by LunaSec and has made organisations such as Apple, Tesla, and Amazon vulnerable to attacks.<\/p>\n<p>The exploit, also known as Log4Shell and tracked as CVE-2021-44228, allows an attacker to inject log messages or message parameters into server logs that load code from a remote server.<\/p>\n<p>IT security company Sophos detected a rapid increase in attacks exploiting Log4J on Sunday, 12 December.<\/p>\n<p>&#8220;Since Dec. 9, Sophos has detected hundreds of thousands of attempts to remotely execute code using the Log4Shell vulnerability,&#8221; said Sophos senior threat researchers Sean Gallagher.<\/p>\n<p>Gallagher highlighted the severity of the Log4J vulnerability.<\/p>\n<p>&#8220;Many software vulnerabilities are limited to a specific product or platform, such as the ProxyLogon and ProxyShell vulnerabilities in Microsoft Exchange. Once defenders know what software is vulnerable, they can check for and patch it,&#8221; he said.<\/p>\n<p>&#8220;However, Log4Shell is a library that is used by many products. It can therefore be present in the darkest corners of an organisation&#8217;s infrastructure, for example any software developed in-house.&#8221;<\/p>\n<p>&#8220;Finding all systems that are vulnerable because of Log4Shell should be a priority for IT security,&#8221; he added.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/427152-high-tech-r20-million-forensic-war-room-to-fight-corruption-in-joburg.html\" target=\"_blank\" rel=\"noopener\">High tech R20 million forensic war room to fight corruption in Joburg<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>There are two vulnerabilities in the first fix released for the Apache Log4J exploit.<\/p>\n","protected":false},"author":341076,"featured_media":414496,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[723,24470,605,5276,75028,75030,20719],"class_list":["post-427942","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-amazon","tag-apache","tag-apple","tag-cyber-security","tag-log4j","tag-log4shell","tag-tesla"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/427942"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=427942"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/427942\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/414496"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=427942"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=427942"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=427942"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}