Log4shell Jndi Exploitation

How to discover, verify, and exploit JNDI/Log4Shell vulnerabilities in Java applications. Use this skill whenever the user mentions Log4j, JNDI, LDAP injection, CVE-2021-44228, Java deserialization, or needs to test for remote code execution through logging libraries. Make sure to use this skill for any Java application security testing involving logging frameworks, especially when HTTP headers, user input, or configuration files might be logged.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/pentesting-web/deserialization/jndi-java-naming-and-directory-interface-and-log4shell commit b52b8a677f

Frequently asked questions

npx skillmds@latest add abelrguezr/log4shell-jndi-exploitation