书签 分享 收藏 举报 版权申诉 / 3
1

类型[20220207]IN11824_信息技术中的系统性漏洞——Log4Shell.pdf

  • 上传人:任**
  • 文档编号:31889
  • 上传时间:2022-06-24
  • 发布时间:2022-02-07
  • 格式:PDF
  • 页数:3
  • 大小:694.87KB
  • CRS INSIGHT Prepared for Members and Committees of Congress INSIGHTINSIGHTi i Systemic Vulnerabilities in Information TechnologyLog4Shell Updated February 7, 2022 There is critical vulnerability in software used by millions of internet servers. Since its discovery both criminals and nation-state actors have reportedly exploited it. It is uncertain how many entities are vulnerable, but it is presumed there are many. This CRS Insight describes the vulnerability and federal government response considerations. Log4Shell Log4j is an open-source tool the Apache Foundation makes available for logging web server activity. To work, Log4J has to access many network services (e.g., network maps and directories). Malicious actors discovered a way to use the Log4j tool to send commands that give them control of the servers. The cybersecurity community named this vulnerability Log4Shell. Log4Shell exploits have been observed to mine cryptocurrencies and expand botnets. Apache Foundation software is very useful and freely available, so it is widely deployed. Hundreds of software projects maintained by the foundation rely on volunteer developers and are supported by donations and sponsorships. Res
    展开阅读全文
    特殊限制:

    部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。

    关 键  词:
    20220207 IN11824_ 信息技术 中的 系统性 漏洞 Log4Shell
    1
    提示  联参智库所有资源均是用户自行上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作他用。
    关于本文
    本文标题:[20220207]IN11824_信息技术中的系统性漏洞——Log4Shell.pdf
    链接地址:https://www.lianhezuozhan.com/doc/31889.html
    1

    客服:010-66465788   北京联参科技有限公司版权所有  工业和信息化部备案/许可证编号:京ICP备2022007273号-1



    联参智库