Case 04856F · Famous breaches · L3 Applied
JNDI strings in the logs
Practise as: Incident drill
Live alertFriday 10 December 2021: your WAF shows thousands of requests with ${jndi:ldap://...} in User-Agent headers hitting 40 public apps, and one Java app server made an outbound LDAP connection on port 1389.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- The outbound LDAP callback means that app likely evaluated the lookup: treat it as potentially compromised
- Isolate that server, capture memory and logs, check for dropped miners, web shells or new users
- Build inventory fast: find Log4j jars (incl. nested in fat JARs) with scanners across all hosts
- Mitigate: patch, remove JndiLookup.class if you cannot, block outbound LDAP/RMI egress, WAF rules as stopgap
- Watch for obfuscated payloads like ${${lower:j}ndi:...} that bypass naive WAF signatures
If the interviewer pushes back
- A vendor appliance you cannot patch runs Log4j. What do you do?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.