5 ms·
A couple of clarifications that i expect everyone knows, but still should be said. In all practical sense, no one "at Apache" has released any remediations for
by mbfg 4y ago
A couple of clarifications that i expect everyone knows, but still should be said.
In all practical sense, no one "at Apache" has released any remediations for log4j. There's just a bunch of random people, probably like 3 around the world, who released these patches.
"how reliant many companies are on third-party and open source code over which they have little control or visibility" - that's crap. They have complete visibility, and a good deal of control. Companies just choose not to spend money doing so. Which is true of their own code, as well.
What the hell is "log4jshell" that is a completely stupid name. It confers some meaning that isn't there.
- richbell 4y ago> What the hell is "log4jshell" that is a completely stupid name. It confers some meaning that isn't there. It's a pun on Log4J and describes the vulnerability: all you need to get reverse shell is for the application to log input. What meaning do you feel it confers that isn't there? (The trend of subsequent vulnerabilities being dubbed "...4Shell" is infuriating, though.)
- freeqaz 4y agoI apologize for accidentally creating a meme here. (I got angry when I saw the recent "ProxyNotShell" vulnerability in the media...) It is an interesting exercise in the power of language though. The name "Log4Shell" was literally picked because there wasn't a CVE and people running searches for "log4j RCE" were seeing a vuln in Log4j v1 from 2016. There needed to be a unique identifier that people could search for and tag on Twitter. The name just... sort of got picked arbitrarily while I was very tired after doing many hours of security research and reading through Enterprise Java code lol. (You're right that "shell" was used to express RCE, ala Shellshock or other major vulns.) I think the subsequent vulns (Spring4Shell, Text4Shell) just use the format of the name to be more catchy and ride the coat tails of Log4Shell's notoriety. (Like a meme!)
- richbell 4y agoYour blog posts were instrumental in response efforts, and it was honestly a great name (in response to a real problem, as you've mentioned), so I'll forgive you. ;) > I think the subsequent vulns (Spring4Shell, Text4Shell) just use the format of the name to be more catchy and ride the coat tails of Log4Shell's notoriety. (Like a meme!) 100%. The problem is that it's not only lazy (like how every controversy is X-gate), it also makes executives and senior leaders shit their pants. Log4Shell was a serious wake-up call for many companies and forced them to take security and software seriously. Subsequent clout-chasing or memed vulnerabilities that evoke its name risk creating "alarm fatigue" — "The Boy Who Cried '4Shell'", so to speak. https://en.wikipedia.org/wiki/Alarm_fatigue https://en.wikipedia.org/wiki/Alarm_fatigue
- mbfg 4y agoit implies a product, like a repl for log4j, to me. So the lazy says, i'm not using log4jshell, so i'm good.