CVE-2021-44228 - Log4j - MINECRAFT VULNERABLE! (and SO MUCH MORE)

Поділитися
Вставка
  • Опубліковано 26 січ 2025

КОМЕНТАРІ • 427

  • @_JohnHammond
    @_JohnHammond  25 днів тому

    hmmmm such video very wow so anyways join my newsletter at jh.live/newsletter and check out jh.live/training for more cybersecurity stuff

  • @GamingHintsify
    @GamingHintsify 3 роки тому +1102

    John out here killing 2 birds with one stone. Showing us the severity of this vuln, but also showing us how to setup a minecraft server

    • @totallynotbluu
      @totallynotbluu 3 роки тому +115

      came for the minecraft server setup, stayed for the cybersecurity discussion

    • @Umar0x01
      @Umar0x01 3 роки тому +2

      haha

    • @guilherme5094
      @guilherme5094 3 роки тому +3

      The hero we need.

    • @dieSpinnt
      @dieSpinnt 3 роки тому

      It's also circular:
      With Minecraft (servers) there is desire for security exploits and botnets, Senpai (as we've seen the children ... or better criminals playing and disintegrating half of the internet several times for ... immature nonsense as the occasion).
      So there is need for security experts, who also play Minecraft, who setup servers or tell how to setup servers correctly(of course, the security has an expiration date:) ) ...
      ... oh and the side-effect, that we get informative high quality videos from John is also nice, thank you:)

  • @Wastelander1972
    @Wastelander1972 3 роки тому +239

    John, you’re getting big out there if you weren’t already. My organization cited this video directly for information on this vulnerability. Very well done.

  • @zihasz5305
    @zihasz5305 3 роки тому +52

    The calculator open up twice at 20:43 because both the server and client logger got the payload. Great video btw!

    • @mylo5641
      @mylo5641 3 роки тому +3

      it actually calls it twice from the server. if you run minecraft on java 7 or earlier it will run on the client as well though

    • @ZeeraaDev
      @ZeeraaDev 3 роки тому +5

      When i tried it myself i also got 2 requests but i think thats because the log message gets proccessed once for the console window and once for the latest.log file

  • @_JohnHammond
    @_JohnHammond  3 роки тому +179

    As Para noted in the comments below, I had a typo while attempting to download the old 1.8.8 version of the PaperMC server. At the time of writing this comment, that old version is still available for download with the right link. ("builds" instead of "build")
    Additionally, the language "zero-day clusterbomb" should be credited to Florian Roth. He described the log4j vulnerability as such, and I just think it is such a perfect name for it.

    • @JosephBrunsman
      @JosephBrunsman 3 роки тому

      Thanks again for all the great content!

    • @zearthus7089
      @zearthus7089 3 роки тому +1

      are Android and iOS Apps and devices will also be affected on this vulnerability issue of Log4j?

    • @Techies06
      @Techies06 3 роки тому +3

      New subscriber here, It is awesome finding someone who can really nerd out on security. What a great video, thank you.

    • @dieSpinnt
      @dieSpinnt 3 роки тому

      Great explanation, thank you for the work and presentation, John!:)
      Now to the superfluous, cynic and schadenfreude-pregnant part: It's the 'ol wisdom -> Java users get what they deserve! Why not install even FLASH?:P
      Sorry for that ... and to you and yours, the community (including hard working Java related folks), I wish a good new year:)

    • @georgehammond867
      @georgehammond867 3 роки тому

      Can you defeat Windows defender? with Log4j true MineCraft!

  • @hardikjain8741
    @hardikjain8741 3 роки тому +42

    I was waiting for John's Detailed video to come out. This is a one-stop shop for all the information you need regaring CVE-2021-44228.
    Thank you

  • @seclilc
    @seclilc 3 роки тому +41

    This is all nuts. Thank you for sharing the nitty and gritty

  • @Flurry17
    @Flurry17 3 роки тому +254

    >Working in IT
    >Wondering what the hell is going why is there so many tickets titled Log4J something
    >Watches the video
    >I'm fucked

    • @aliencatmeow
      @aliencatmeow 3 роки тому +12

      I also work in IT. We got a bunch of log4j tickets as well and i just remembered the new vulnerability, so I was like someone's patching it right?

    • @kamilkicka4455
      @kamilkicka4455 3 роки тому +14

      I am Security guy and all I can say Is that was busy Monday

    • @Jaycomma
      @Jaycomma 2 роки тому

      @@aliencatmeow Wow, where do you work where people are actually targeting you?

    • @caboose22320
      @caboose22320 11 місяців тому

      @@aliencatmeow answer

    • @ۥٴٴۥۥٴٴۥ
      @ۥٴٴۥۥٴٴۥ 24 дні тому

      @@aliencatmeow answer

  • @matthewbolan8154
    @matthewbolan8154 3 роки тому +65

    Not the most pleasant way for our worlds to collide, but a good video!

  • @kevin3434343434
    @kevin3434343434 3 роки тому +128

    Its amazing how much of the world is built on free labor and how little everyone values open source.

    • @Time4Technology
      @Time4Technology 3 роки тому +5

      Wise words.

    • @RadikaRules
      @RadikaRules 2 роки тому +2

      Kind of a microcosm of capitalism if you think about it

  • @IONJigZz
    @IONJigZz 3 роки тому +84

    "Hippedy hoppedy, your code is now my property" that cracked me up ngl

    • @xhaser56
      @xhaser56 3 роки тому +2

      I HAVE to remember this quote! 😂🤣😂🤣

    • @the23er
      @the23er 3 роки тому +2

      Needed as Merch

    • @kitrodriguez992
      @kitrodriguez992 3 роки тому

      Reminded me of Dani

    • @kimobonbon7
      @kimobonbon7 2 роки тому

      tbh me too

  • @Cyberducky
    @Cyberducky 3 роки тому +10

    This video is amazing, it combines my all-time favorite game with exploiting a vulnerability and to top it all off the video is made by the incredibly talented John Hammond. 10/10 would watch again.

  • @GunRotMG
    @GunRotMG 3 роки тому +62

    Note, at 8:55 the Version is still available, you made a typo in the URL, its supposed to be /builds/ instead of /build/

  • @rajeshkhatwani
    @rajeshkhatwani 3 роки тому

    One of the best Log4j demo, learned so much John. Big Thumbs Up! Thanks!

  • @oliviadrinkwine1411
    @oliviadrinkwine1411 3 роки тому +8

    A friend got ratted with this vulnerability so thanks for sharing and spreading the news

  • @MattMcT
    @MattMcT 3 роки тому +1

    you're super inspiring John. Thank you so much for your work and vibe!

  • @strouja
    @strouja 3 роки тому +1

    Thanks for this, awesome work. Very impressive.

  • @Shad33
    @Shad33 3 роки тому

    Was waiting on your video so I could better understand and you most def did not dissapoint. I appreciate your work

  • @reymarckessaguirre5082
    @reymarckessaguirre5082 3 роки тому +1

    There we go, been waiting for this vid since the panic yesterday.

  • @brettnieman3453
    @brettnieman3453 3 роки тому +1

    Great video, John!

  • @kartik180rajesh1
    @kartik180rajesh1 3 роки тому

    Very well demonstrated! Understood the whole pipeline from the setup to execution

  • @AlphaZeroOmega
    @AlphaZeroOmega 3 роки тому

    Thanks John! Great video showcasing this new vulnerability. I found it to be very well explained and demonstrated.

  • @atsekbatman
    @atsekbatman 3 роки тому

    Thanks for that video and the explanation on this topic!

  • @VishalSharma-gt1hy
    @VishalSharma-gt1hy 3 роки тому +4

    i can finally setup my first minecraft server. Thanks to john.

  • @Methodmanishe
    @Methodmanishe 3 роки тому

    Absolutely amazing! Thank you for sharing it and giving it a high quality explanation!

  • @SamAndrew27
    @SamAndrew27 3 роки тому

    My work week has been utter HELL because of log4j!! So glad it's a holiday next week!

  • @_notch
    @_notch 3 роки тому +2

    Great video as always, John. This vulnerability is quite disturbing with how old it potentially might be. I remember implementing log4j in several projects, possibly including minecraft.

  • @DonRichards
    @DonRichards 3 роки тому

    Something else that makes this massive is Apache Solr uses Log4j. Solr is in a LOT of things and typically gets little attention. Thanks for the demo! Super helpful!

  • @sauloguilhermino2831
    @sauloguilhermino2831 3 роки тому

    Great great great explanation, John. Thank you for the video and also the testing tool, it'll be very useful for me and my team for the next few days :)

  • @ErnestoVazquezChoby1000
    @ErnestoVazquezChoby1000 3 роки тому

    I loved the hippity hoppity, your code is now my property lol. Great video!!!!

  • @HAGSLAB
    @HAGSLAB 3 роки тому +1

    Good video as always, very informative! 🧑‍💻

  • @Z3kyTw0
    @Z3kyTw0 3 роки тому +1

    John giving us gifts with these videos, dude is straight fire!

  • @lfcbpro
    @lfcbpro 3 роки тому

    Great vid John, found it very interesting and hopefully this will help a lot of admins.

  • @MonoJaviX
    @MonoJaviX 3 роки тому

    Great video, very educative. Thanks for the time you took to make this one.

  • @scottangelides9237
    @scottangelides9237 3 роки тому

    i was looking for a video to explain the vuln and of course mr hammond had one out already you are a saint

  • @kclok323
    @kclok323 3 роки тому

    Great John! Thanks for the video.

  • @MarcoMassieri
    @MarcoMassieri 3 роки тому

    amazing that you have already set up a room for log4j on thm !!

  • @unit4246
    @unit4246 3 роки тому

    I wait for this video all day you are amazing 🤩

  • @embly2319
    @embly2319 3 роки тому +45

    You should do more stuff like this, I know it's not everyday that an exploit like this is discovered and CTF's are likely far easier for you to make but live exploitation demos like this are super cool.

    • @Hope-kf1nl
      @Hope-kf1nl 3 роки тому +2

      That's what most CTFs are... Previous RCEs and SSRF exploitation in old software... Lmao.

    • @malfoytech4601
      @malfoytech4601 3 роки тому +1

      Agreed.

    • @embly2319
      @embly2319 3 роки тому +2

      @@Hope-kf1nl Not really. CTF's don't show the blue team side and showing how to make your own test environment is a valuable skill. I'd like to see more of both.

    • @Hope-kf1nl
      @Hope-kf1nl 3 роки тому

      @@embly2319 I'm a little confused by your question. You'd want him to create a test environment for every single video?
      A lot of John's content is educational from a Red Team perspective. He works full time and I doubt he has time to setup a test environment (which has it's own caveats and bugs) as well as exploit it.
      I'd assume he'd need to put a lot more work into each video. Which means less time he has to get things posted. Believe it or not, we all have fulltime jobs paying over 100k+ in the security field that keeps the lights on.
      I doubt John wants to quit his day job and just focus on trying to post video that would likely require 10x the work for very little reward...

    • @embly2319
      @embly2319 3 роки тому +1

      @@Hope-kf1nl Didn't ask you a question anywhere in my comments. I acknowledged that this takes more time in my first comment. I dont think John would be in any danger of becoming homeless if he started doing more vids like this, that's kind of ridiculous. My original point still stands that all of the things being show cased are valuable skills for newbies, and imo it makes for more interesting content. There isn't allot of high quality content like this on UA-cam so it would be nice to have more.

  • @testtest2910
    @testtest2910 3 роки тому

    Amazing video John!!

  • @Angie1R
    @Angie1R 3 роки тому

    Thank you, good work done! Nicely explained, demonstrated and remedied. 👏

  • @0dayCTF
    @0dayCTF 3 роки тому +8

    I heard “0day” 4 times and I appeared 😀

  • @dj_bsec
    @dj_bsec 3 роки тому

    Thanks for helping get out the info John!

  • @melvin16
    @melvin16 3 роки тому

    Awesome presentation. Thank you :)

  • @GeorgFranz
    @GeorgFranz 3 роки тому

    Thank you very much for your insights, you have opened my eyes!

  • @venkateshnambi1576
    @venkateshnambi1576 2 роки тому

    Excellent video.. about log4j with practical explanation.

  • @sayaf9393
    @sayaf9393 3 роки тому

    Thx for a video. Learned a lot from u 🙌

  • @AsmodeusMictian
    @AsmodeusMictian 3 роки тому

    Thanks for the vid man!

  • @trilogiam
    @trilogiam 3 роки тому

    Brilliant! All 34 minutes of it!

  • @haxguy0
    @haxguy0 3 роки тому

    Hey thanks for sharing this John

  • @manan5
    @manan5 3 роки тому

    lol so many cuts must be a real tough job making this video. Thanks!

  • @tomasofficial.
    @tomasofficial. 3 роки тому

    This video is AMAZING! You covered everything, i dont regret being a subscriber. Thanks John for another good video, the new people that came from a gaming community and dont know you are really losing the game 😂

  • @flatlinejimbob
    @flatlinejimbob 3 роки тому

    Amazing work, thank you!

  • @wise_one45
    @wise_one45 3 роки тому

    Thanks for the educational POC 👊🏾

  • @CrashLoopBackOff-K8s
    @CrashLoopBackOff-K8s 3 роки тому

    Followed you on twitter a long while back, but wanted to sub and drop a comment here, as well. Appreciate all you do for the larger community. Thank you.

  • @gabrield6425
    @gabrield6425 3 роки тому

    I like the waiting screen John!

  • @hash_fpv
    @hash_fpv 3 роки тому

    Thank you John for the video.

  • @davisbugz
    @davisbugz 3 роки тому

    Thanks John. Great Breakdown...

  • @Daedwartin2
    @Daedwartin2 3 роки тому +2

    And for those who found out on the programming side of things...Best of Luck in this yet to be determined period of hell as you drop everything to fix this.

  • @tomasgorda
    @tomasgorda 3 роки тому

    Great explanation. Thank you 👍

  • @shahafl
    @shahafl 3 роки тому

    Super interesting! Thank you!

  • @shivaganesh6939
    @shivaganesh6939 3 роки тому

    Hunter!! Hacker!! Great video ever! The thrill of pwning the system!

  • @thomashedrick8446
    @thomashedrick8446 11 місяців тому

    Great tutorial btw John!! I'm a sysadmin and feel like a noob when it comes to shit like this I think if there was a GUI for these servers you're spinning up it would make it much easier to understand but I know that's not the case.

  • @yankeesouth
    @yankeesouth 3 роки тому +35

    I know we are about to hear from John Hammond but has anyone asked what JaRule thinks of the log4j zero day?

    • @seclilc
      @seclilc 3 роки тому +1

      Lol

    • @frosecold
      @frosecold 3 роки тому +1

      I don't get this joke... Like, at all

    • @TheSeakr
      @TheSeakr 3 роки тому +1

      @@frosecold You should ask JaRule why its funny

    • @asii_k
      @asii_k 3 роки тому +6

      @@frosecold Dave Chappelle had a special from 2005 or so where he talks about seeing JaRule being interviewed after 9/11 and the joke goes on basically as josh outlined there. It's a great special actually

    • @kc-me6wl
      @kc-me6wl 3 роки тому

      looooool too good

  • @mohemmedahmed7478
    @mohemmedahmed7478 3 роки тому

    Nice and thank you for this video

  • @koi7290
    @koi7290 2 роки тому

    Minecraft is just the tip of the iceberg no sentence has made me more invested before

  • @spider_corsa
    @spider_corsa 3 роки тому

    This kind of instability of the digital world is always terrifying me. Like the Jurrasic Park movie. Always about the budget and deadlines of the companies which cause cheap and lazy solutions, but the marketing is selling these products to key-positions and therefore it's affecting everybody. Thank you and the other talented hackers in the world who are working for us instead of against us! Open source forever!

  • @joshua-beck
    @joshua-beck 3 роки тому +2

    This is a great explainer!

  • @SamsonPavlov
    @SamsonPavlov 3 роки тому +2

    Thanks professor John... I believe Grinch Enterprises will use this to attack Santa... If not this year, next for sure... We'll be ready...💪🎄

  • @mindesh
    @mindesh 3 роки тому

    If you implement proper outbound traffic filtering, even if your server is vulnerable, this will not work. Basic hygiene. And this is so shockingly underrated.

  • @Andy-jz1zw
    @Andy-jz1zw 3 роки тому

    Merry Grichmas John

  • @captainkatz1775
    @captainkatz1775 3 роки тому

    Really dope video 😃😃😃

  • @custume
    @custume 3 роки тому

    great work, keep up the good work

  • @hamzahwahab2286
    @hamzahwahab2286 Рік тому

    that is some juicy detailed of log4j, i am lucky of his subscriber

  • @farpasmasterfarpador9092
    @farpasmasterfarpador9092 3 роки тому +1

    What would happen if Windows Defender was active at 21:50?

  • @andycremeans
    @andycremeans 3 роки тому

    Keep up the good work John.

  • @abdeslam_blc
    @abdeslam_blc 3 роки тому

    Thanks for the information, see you soon

  • @fallenveye
    @fallenveye 3 роки тому +1

    You can't execute code on clients connected to minecraft server, am i right? I've seen few videos says opposite, but that sounded wrong. Can you tell something about it?

  • @mrtnsgs
    @mrtnsgs 3 роки тому

    This is amazing!!! Thanks

  • @ryzenforce
    @ryzenforce 3 роки тому +3

    3 Billion devices... Oracle is showing that on their installer/updater since the last 15 years...

    • @w1d3r75
      @w1d3r75 3 роки тому +1

      Yeah. Nowadays it's 9/12 Billion devices. Java runs the world 💪

  • @francisreidjr3788
    @francisreidjr3788 3 роки тому

    Thanks John great work

  • @BobBob-qm2bm
    @BobBob-qm2bm 3 роки тому +4

    You need cyber running shoes to keep up with John - still trying to decipher whether or not he ever pause long enough to takes a breath :)

  • @nathansnow
    @nathansnow 3 роки тому

    Hippity hoppity your code is now my property 😆 that's gold

  • @tkdazzler1-130
    @tkdazzler1-130 3 роки тому

    I really love your videos. I am not a fan of the "omg face" on the thumbnails. It is a physcological ploy (if you did not know) to get more views. However, you are the last channel I still watch with these thumbnails because your knowledge is legit (I click do not recommend channel to ALL other channels that use this ploy) but not yours. It's a bit goofy and juxtaposed to your legendary teaching and knowledge :)

  • @devinbrooks136
    @devinbrooks136 3 роки тому

    Great info for someone working in a SOC that's for sure.

  • @Mackenzieadventures1
    @Mackenzieadventures1 3 роки тому +2

    We’ve been dealing with this at work, many of our SAP systems run JAVA. :(

  • @xshadowcasterx
    @xshadowcasterx 3 роки тому

    Awesome video as always, that shirt is dope! Where can I snag one?

  • @Unstable_dio
    @Unstable_dio 3 роки тому +2

    "Hippity hoppity, your code is now my property"

  • @bloodynoobtubename
    @bloodynoobtubename 3 роки тому +1

    Regarding the industry chatter, the toxic arrogance is probably my biggest issue with the security industry. I used to work as a security analyst, and for the last two years have been working as a software engineer. I know first hand what it's like to see vulnerabilities exploited, and I know what it's like to push out code fit for use on a deadline. It's SUUUUPER easy to play Captain Hindsight and tell developers to grow up, not so easy to be a developer with a full time job, building an open source product in their spare time.

  • @thomaspeterson2568
    @thomaspeterson2568 3 роки тому

    The github repo at 3:40 seems to have been removed.. Interesting..

  • @wtfdoiputhere
    @wtfdoiputhere 3 роки тому

    legend says Shodan is poppin rn

  • @zuberkariye2299
    @zuberkariye2299 3 роки тому

    Thanks for the vid!

  • @In-ShaMbLeS
    @In-ShaMbLeS 3 роки тому +1

    Wayback machine still has the downloads for the papermc 1.8.8

  • @Alterpalm
    @Alterpalm 3 роки тому

    Santa's bag of toys was a piece of cake video, almost 0 level difficulty 😎
    But this...🤯 Very fast to me to understand and track all the steps.
    No hate, video is great as always)

  • @blademasterz4612
    @blademasterz4612 2 роки тому +1

    Rust version of Minecraft when?

  • @TheVertical92
    @TheVertical92 3 роки тому

    1:43 You did your best 😜

  • @dafelix
    @dafelix 3 роки тому

    I think you forgot the timestamps. Great video, this is gonna bring a lot of people to your channel

  • @betorcsx
    @betorcsx 3 роки тому +3

    Thx Ed Sheeran for sharing this PoC with us. Cheers

  • @jonda_mc
    @jonda_mc 10 місяців тому +1

    Is there something similar for newer versions of minecraft e.g. 1.20.1?

  • @krispyking2450
    @krispyking2450 3 роки тому

    how was this only a month ago it feels like 2 weeks ago