Page 1 of 1

log4j

Posted: Tue Dec 21, 2021 5:46 pm
by Jaymon
Damn you log4j. This was supposed to be a nice and slack week. easy easy, nobody at work, just watch some videos and eat christmas cookies. but noooo, somebody had to go and vulnerability the entire god damn internet, and now I have to work my ass off.

stupid hackers, we hates them.

Re: log4j

Posted: Tue Dec 21, 2021 6:00 pm
by telcta
It was this time last year I was wrapping up my job and retiring. I can't imagine getting hit with this now during the holidays. We have a few products that have log4j heavily embedded... my co-worker has basically shut everything down and will only run some services when using a VPN.

He said the only good thing that came out of this is: https://log4jmemes.com/

This would be me...
Enlarge Image

Re: log4j

Posted: Tue Dec 21, 2021 8:36 pm
by hepcat
I’ve deployed updated war files twice in 3 days over this exploit. Thankfully, we’re moving away from deployments using log4j though, so it’s just some legacy systems.

Re: log4j

Posted: Tue Dec 21, 2021 10:26 pm
by Zaxxon
It's a pain in the ass.

Re: log4j

Posted: Tue Dec 21, 2021 10:46 pm
by coopasonic
Yup, last week was supposed to be the quiet week, after the implementation freeze and before everyone started their vacations. Haha, nah, how about one of the biggest fire drills we have ever seen instead?

Jenkins was crying for mercy all week.

Re: log4j

Posted: Tue Dec 21, 2021 11:39 pm
by malchior
The good thing is we got to practice updating it multiple times. It has to be finally fixed now, right? :doh:

Re: log4j

Posted: Wed Dec 22, 2021 1:54 pm
by hitbyambulance
i remember using this in my Java certification class

Re: log4j

Posted: Wed Dec 22, 2021 3:06 pm
by gilraen
The Apache library version that we use in our software is so old, it's actually not affected by the exploit. Win!

Re: log4j

Posted: Thu Dec 23, 2021 12:52 pm
by naednek
gilraen wrote: Wed Dec 22, 2021 3:06 pm The Apache library version that we use in our software is so old, it's actually not affected by the exploit. Win!
hah same boat here.

Our linux guy is soaking that up.

We have found 30 + servers so far.

Re: log4j

Posted: Thu Dec 23, 2021 2:01 pm
by Pyperkub
Jaymon wrote:Damn you log4j. This was supposed to be a nice and slack week. easy easy, nobody at work, just watch some videos and eat christmas cookies. but noooo, somebody had to go and vulnerability the entire god damn internet, and now I have to work my ass off.

stupid hackers, we hates them.
Last year it was the SolarWinds hack. The slack weeks around the holidays don't apply anymore.