5 ms·
This JNDI "feature" is 8 years old. It was merged in 2013 from what I have seen, and has been defended by some as an "useful" feature. It has been known since a
by mol4711 5y ago
This JNDI "feature" is 8 years old. It was merged in 2013 from what I have seen, and has been defended by some as an "useful" feature. It has been known since at least BlackHat 2016 presentation that this is an incredibly dangerous and stupid thing to keep.
cricket noises nobody reacted until now when minecraft servers got hacked.
- js8 5y ago> nobody reacted until now when minecraft servers got hacked That shows which part of the IT industry is really needed.. :-)
- bopbeepboop 5y agoOn average, humans spend five days of their life watching Minecraft related content. Google recently had a banner announcing a trillion hours of Minecraft content watched; there are roughly 8 billion humans. So on average, a human has watched ~125 hours of Minecraft content. I think it’s just InfoSec has been too busy playing secret squirrel to secure our infrastructure: - SolarWinds - MS Exchange - log4j - Minecraft
- bombcar 5y agoMore importantly Minecraft servers are a target of convenience that both could and would be attacked by script kiddies. The open question is did anyone exploit this quietly and targeted before?
- jethro_tell 5y agoOf coarse. Especially if it was known since black hat 2016.
- josefx 5y ago> and has been defended by some as an "useful" feature. I would say the feature is useful but the implementation is insane. I would expect a SQL prepared statement approach, only contents of the statement / format string are resolved. Interpreting variables in user provided input just asks for SQL injection attacks and needs to be either prohibited or extremely restricted.
- abhishekjha 5y agoI guess you are referring to this[0]. I am surprised if it was known that early then why did it take so long to find the issue? Or were exploits already run earlier and nobody reported? [0]https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-...
- joe_guy 5y agoI only skimmed it but couldn't find any references to log4j.
- avidphantasm 5y agoThis whole fiasco is an argument to keep things simpler whenever possible.