Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

CVE-2021-44228 - Log4j - Minecraft Vulnerable and So Much More

John Hammond via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course examines the Log4Shell vulnerability in Java's Log4j package through demonstrations against vulnerable applications, including unpatched Minecraft servers. It covers remote code execution, reverse shells, detection, bypasses, vulnerability testing, and defensive industry responses.

Syllabus

- Introduction.
- Tweet on gaining RCE via Minecraft.
- Overview of topics covered in video.
- Context surrounding Log4j exploit.
- Blog posts & Github repositories on CVE-2021-44228.
- [Demo] Exploiting Log4j to get a callback to attacker-controlled server.
- [Demo] Exploiting Log4j via unpatched Minecraft server (Spawning calc.exe).
- [Demo] Exploiting Log4j via unpatched Minecraft server (Spawning a reverse shell).
- How the industry is responding from a defense perspective.
- Industry chatter surrounding CVE-2021-44228.
- Blog post discussion.
- Open Source Log4Shell Vulnerability Tester.
- Conclusion.

Taught by

John Hammond

Reviews

Start your review of CVE-2021-44228 - Log4j - Minecraft Vulnerable and So Much More

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.