Oxeye mitigates Log4Shell vulnerability

Issue 8 2021 Information Security, Products & Solutions

Oxeye, a technology innovator in cloud-native application security testing solutions, today unveiled the first 2022 open-source initiative with the introduction of Ox4Shell. The free open-source payload deobfuscation tool is the first in a series of solutions to be developed by Oxeye to assist developers, AppSec professionals and the open-source community.

Ox4Shell is designed to confront what some are calling the ‘Covid of the Internet’, known as the Log4Shell zero-day vulnerability. To counter a very effective obfuscation tactic used by malicious actors, Oxeye’s new open-source tool (available on GitHub) exposes hidden payloads which are actively being used to confuse security protection tools and security teams.

As reported by experts, organisations globally continue to experience remote code attacks and the exposure of sensitive data due to the pervasive Log4Shell vulnerability. Discovered in Apache’s Log4j, a logging system in widespread use by web and server application developers, the threat makes it possible to inject text into log messages or log message parameters, then into server logs which can then load code from a remote server for malicious use. Apache has given Log4Shell a Common Vulnerability Scoring System (CVSS) severity rating of 10 out of 10, the highest possible score. Since then, researchers found a similar vulnerability in the popular H2 database. The exploit is simple to execute and is estimated to affect hundreds of millions of devices.

According to Jonathan Care, senior director analyst at Gartner, “The Log4j vulnerability is extremely widespread and can affect enterprise applications, embedded systems and their sub-components. Java-based applications including Cisco Webex, Minecraft and FileZilla FTP are all examples of affected programs, but this is by no means an exhaustive list. The vulnerability even affects the Mars 2020 helicopter mission, Ingenuity, which makes use of Apache Log4j for event logging.”

As part of a new open-source initiative for 2022, Oxeye is unveiling the first in a series of contributions designed to strengthen security efforts by deobfuscating payloads often coupled with Log4j exploits. Ox4Shell exposes obscured payloads and transforms them into more meaningful forms to provide a clear understanding of what threat actors are trying to achieve, allowing the concerned parties to take immediate action and resolve the vulnerability.

The Log4j library has a few unique lookup functions that permit users to look up environment variables, Java process runtime information and so forth. These enable threat actors to probe for specific information that can uniquely identify a compromised machine they’ve targeted. Ox4Shell enables you to comply with such lookup functions by feeding them mock data that you control.

“Difficulties in applying the required patching to the Log4Shell vulnerability means this exploit will leave gaps for malicious attacks now and in the future. The ability to apply obfuscation techniques to payloads, thereby circumventing the rules logic to bypass security measures also makes this a considerable challenge unless the proper remedy is applied,” said Daniel Abeles, head of research at Oxeye. Deobfuscation will be critical to understanding the true intention(s) of attackers. Ox4Shell provides a powerful solution to address this and as a supporter of the open-source community, we are proud to contribute and make it available through GitHub.”

Find out more at www.oxeye.io/ox4shell-deobfuscate-log4shell




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
New fire blanket for lithium-ion battery fires
Fire & Safety Products & Solutions
SafeQuip launched its newly developed range of high-performance, multi-use lithium-ion battery fire blankets, specifically designed to address fires involving devices with lithium-ion batteries, providing a crucial tool for safety in environments where these batteries are in use.

Read more...
SafeQuip launches lithium-ion battery fire extinguishers
Fire & Safety Products & Solutions
[Sponsored] SafeQuip has launched the SANS 1910-2022 approved Lith-Ex fire extinguisher range, which carries NTA 8133:2021 (KIWA/POOO55865) test approval, which proves its lithium-ion battery fire extinguishing capability.

Read more...
Watermist suppression in mining
FS Systems Fire & Safety Mining (Industry) Products & Solutions
Watermist suppression systems are highly effective in suppressing flames and controlling heat spread, especially in confined spaces commonly found in mining environments, by generating fine droplets with an increased surface area, enabling rapid heat absorption and cooling during fire incidents.

Read more...
FS partners with Oculus
FS Systems Fire & Safety Products & Solutions
FS Systems announced a strategic partnership with Oculus Innovations to combine the company’s integrated security management solutions with Oculus Innovations’ expertise in designing state-of-the-art control room environments.

Read more...
Quality fire detection installation at Baywear Clothing
G2 Fire Fire & Safety Industrial (Industry) Products & Solutions
JZL Projects and Solutions was asked to provide a comprehensive yet cost-effective and reliable fire detection solution for Baywear Clothing that would be installed with minimum disruption to the factory.

Read more...
From wireless alarms to smart homes
Elvey Security Technologies Perimeter Security, Alarms & Intruder Detection Products & Solutions
The final brand SMART Security Solutions features in its discussions with companies operating in South and southern Africa’s detection and alerting technologies market is DSC, distributed in the region by Elvey Security Technologies.

Read more...
The AX Hybrid PRO Series offers reliable wired and wireless protection
Hikvision South Africa Editor's Choice Perimeter Security, Alarms & Intruder Detection Products & Solutions
Hikvision has announced the launch of a new AX Hybrid PRO alarm system with innovative Hikvision ‘Speed-X’ transmission technology. This system offers reliable wired protection while delivering expanded flexibility with seamless wireless integration.

Read more...
Advanced Perimeter Intrusion Detection Systems
XtraVision OPTEX Technews Publishing Modular Communications Perimeter Security, Alarms & Intruder Detection Integrated Solutions Products & Solutions
Making full use of fibre installations around the perimeter by adding Perimeter Intrusion Detection Systems means you can easily add another layer of security to existing surveillance and fencing systems.

Read more...
There is a SaaS for everything, but at what cost, especially to SMEs?
Editor's Choice Information Security Security Services & Risk Management
Relying on SaaS platforms presents significant cybersecurity risks as the number of providers in your landscape increases, expanding your attack surface. It is important to assess the strength of the SaaS providers in your chain.

Read more...