Open cardosec

Case 04856F · Famous breaches · L3 Applied

JNDI strings in the logs

Practise as: Incident drill

Live alertFriday 10 December 2021: your WAF shows thousands of requests with ${jndi:ldap://...} in User-Agent headers hitting 40 public apps, and one Java app server made an outbound LDAP connection on port 1389.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. The outbound LDAP callback means that app likely evaluated the lookup: treat it as potentially compromised
  2. Isolate that server, capture memory and logs, check for dropped miners, web shells or new users
  3. Build inventory fast: find Log4j jars (incl. nested in fat JARs) with scanners across all hosts
  4. Mitigate: patch, remove JndiLookup.class if you cannot, block outbound LDAP/RMI egress, WAF rules as stopgap
  5. Watch for obfuscated payloads like ${${lower:j}ndi:...} that bypass naive WAF signatures

If the interviewer pushes back

  • A vendor appliance you cannot patch runs Log4j. What do you do?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.