Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Midjack
Dec 24, 2007



be well

Adbot
ADBOT LOVES YOU

hobbesmaster
Jan 28, 2008

FacelessVoid posted:

lol i'm pulling all-nighter to get this log4j fix into production before the holiday freeze. :suicide:

don't worry, if you miss it you can just use log4j to push an update to production!

akadajet
Sep 14, 2003

hobbesmaster posted:

don't worry, if you miss it you can just use log4j to push an update to production!

yeah just use one of those self-patching rce implementations and call it a night lol

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

hobbesmaster posted:

don't worry, if you miss it you can just use log4j to push an update to production!

:thurman:

pseudorandom name
May 6, 2007

Subjunctive posted:

wait, nis? does that mean you can stick a class file in your GECOS field and win the prize?

I think NIS is a simple read-only mapping to RFC2307 semantics, which can't story any of the fancy objects

edit: oh, there's an RFC explaining how to store a Java object in an LDAP record: https://www.ietf.org/rfc/rfc2713.txt. the '90s were a wild and crazy time.

pseudorandom name fucked around with this message at 03:33 on Dec 14, 2021

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer

FacelessVoid posted:

lol i'm pulling all-nighter to get this log4j fix into production before the holiday freeze. :suicide:

gotta push out that yule log4j before the 25th

ewiley
Jul 9, 2003

More trash for the trash fire

pseudorandom name posted:

I think NIS is a simple read-only mapping to RFC2307 semantics, which can't story any of the fancy objects

edit: oh, there's an RFC explaining how to store a Java object in an LDAP record: https://www.ietf.org/rfc/rfc2713.txt. the '90s were a wild and crazy time.

gonna go ponder some inter-ORBs

Hed
Mar 31, 2004

Fun Shoe

pseudorandom name posted:

I think NIS is a simple read-only mapping to RFC2307 semantics, which can't story any of the fancy objects

edit: oh, there's an RFC explaining how to store a Java object in an LDAP record: https://www.ietf.org/rfc/rfc2713.txt. the '90s were a wild and crazy time.

lmfao thank you for this

ate shit on live tv
Feb 15, 2004

by Azathoth
I'm glad the place I work has a general "no java" policy. A few of our dumbass systems/infrastructure applications etc use java, of course, but none of our prod stuff does.

Perplx
Jun 26, 2004


Best viewed on Orgasma Plasma
Lipstick Apathy
good thing tomcat doesn't use log4j by default, otherwise I'd have to fix some poo poo, i just had to upgrade some unifi controllers that are practically unreachable

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer
They shoot horses dont they?

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
comedy logstash is affected by this

Kazinsal
Dec 13, 2011



Lain Iwakura posted:

comedy logstash is affected by this

lol I wonder if our sales guys still use kibana etc for their analytics

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
there are a few threat platforms that use ELK in some fashion and are affected

ask me how i know

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
i am sure this appeared in here already but

https://twitter.com/TheASF/status/1400875147163279374

Shame Boy
Mar 2, 2010

Lain Iwakura posted:

there are a few threat platforms that use ELK in some fashion and are affected

ask me how i know

because you're my coworker who spent the entire day complaining to me about how the ELK stack is affected :v:

animist
Aug 28, 2018

pseudorandom name posted:

I think NIS is a simple read-only mapping to RFC2307 semantics, which can't story any of the fancy objects

edit: oh, there's an RFC explaining how to store a Java object in an LDAP record: https://www.ietf.org/rfc/rfc2713.txt. the '90s were a wild and crazy time.

this rules. why does anybody use json when we could be using pojo-over-LDAP

fins
May 31, 2011

Floss Finder
just had a handover meeting, guy who's fleeing for greener pastures just described his method for getting rid of "that annoying java popup". it involves disabling "all that sandbox crap". fml.

Carbon dioxide
Oct 9, 2012

ZeusCannon posted:

People keep giving me looks when i say assume you are vulnerable, act like you are about to be popped. Patch now.

Like im the ITsec equivalent of the end of times sandwhich board man.

But i feel like thats a reasonable stance. Check your poo poo. Patch it if you can. Get your walls up.

Yep. That's basically what the relevant Dutch government department is saying.

Speaking of, they made a nice github repo with a list of known vulnerable apps and a lot of information about testing for and mitigating vulns. It is actively being updated. May it help you.

https://github.com/NCSC-NL/log4shell

Carbon dioxide
Oct 9, 2012

Excuse me what the gently caress

https://twitter.com/ncweaver/status/1470453024870912000

Cybernetic Vermin
Apr 18, 2005


ah, someone posted that in another thread, and we were wondering why (the base why is because url's compare equal based on actual host rather than hostname, but why it does that). luckily the twitter thread has a very likely answer, checking actual origin host as part of ye olde security model for applets

pseudorandom name
May 6, 2007

animist posted:

this rules. why does anybody use json when we could be using pojo-over-LDAP

you mock but there was a bunch of CVEs 5-10 years ago when people discovered that Ruby and Python etc. supported arbitrary object construction in their JSON/YAML/XML serialization APIs

evil_bunnY
Apr 2, 2003

pseudorandom name posted:

edit: oh, there's an RFC explaining how to store a Java object in an LDAP record: https://www.ietf.org/rfc/rfc2713.txt. the '90s were a wild and crazy time.
JFC

Cybernetic Vermin
Apr 18, 2005

pseudorandom name posted:

I think NIS is a simple read-only mapping to RFC2307 semantics, which can't story any of the fancy objects

edit: oh, there's an RFC explaining how to store a Java object in an LDAP record: https://www.ietf.org/rfc/rfc2713.txt. the '90s were a wild and crazy time.

i mean, just the data of an object, i don't think this is any worse than json, and arguably better since there is no eval() solution to tempt anyone

bleeding kansas
Nov 15, 2019

quote it a million times

i solelmeluely vow i will root the rover

bleeding kansas
Nov 15, 2019
no power on earth can stop me

... but what about beyond?

Subjunctive
Sep 12, 2006

✨sparkle and shine✨


this is from using j.n.URL for origin checks, DNS rebinding attacks and all that fun notwithstanding. people should be using j.n.URI for most things anyway, but I bet if we take a nice drink of water and open up GitHub code search etc etc

e: beaten!

git apologist
Jun 4, 2003

how can a helicopter be ‘powered’ by a logging library

evil_bunnY
Apr 2, 2003

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html

another chrome CVE, already in the wild

cinci zoo sniper
Mar 15, 2013




Gentle Autist posted:

how can a helicopter be ‘powered’ by a logging library

have you tried expelling logs downwards

olorum
Apr 24, 2021

Lain Iwakura posted:

gonna plead ignorance here but can you do this nested

so like...

code:
$lower:{$upper:l}
would that be valid?

code:
$lower:{$lower:{$upper:l}}
also comes to mind if so

Or this:

https://twitter.com/Laughing_Mantis/status/1470526083271303172

r u ready to WALK
Sep 29, 2001

lmao why is Java this dumb

cinci zoo sniper
Mar 15, 2013




java more like jawohl

cinci zoo sniper
Mar 15, 2013




re: paypal mystery - today i got phone 2fa code as i opened the payment form, but before entering my password and pressing “log in”

Beve Stuscemi
Jun 6, 2001




Gentle Autist posted:

how can a helicopter be ‘powered’ by a logging library

lol it’s pretty obvious, there is a Bitcoin miner installed via log4j RCE that generates enough heat to produce lift.

Grace Baiting
Jul 20, 2012

Audi famam illius;
Cucurrit quaeque
Tetigit destruens.



rafikki posted:

I saw some write ups saying yes.

*jndi:dns*
*jndi:ldap*
*jndi:rmi*
*jndi:nis*
*jndi:nds*
*jndi:corba*
*jndi:iiop*

is the list I saw

*jndi:znuts*

Shame Boy
Mar 2, 2010

Jim Silly-Balls posted:

lol it’s pretty obvious, there is a Bitcoin miner installed via log4j RCE that generates enough heat to produce lift.

i mean spacecraft and rovers do need a bunch of heaters to keep their systems (especially batteries) at temperatures they actually work at, and it's not like the deep space network has anything better to do than transmit the entire bitcoin blockchain to mars

shame on an IGA
Apr 8, 2005

I'm a goddamn wastewater treatment operator not a computer toucher and yet my entire morning has been about trying to get an internal service patched to fix log4j after the vendor provided an update

cinci zoo sniper
Mar 15, 2013




shame on an IGA posted:

I'm a goddamn wastewater treatment operator not a computer toucher and yet my entire morning has been about trying to get an internal service patched to fix log4j after the vendor provided an update

have you tried flushing it off and on again

Adbot
ADBOT LOVES YOU

shame on an IGA
Apr 8, 2005

the thousand gallon tank of sulfuric acid is a more and more tempting solution honestly

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply