[20220207]IN11824_信息技术中的系统性漏洞——Log4Shell.pdf
-
资源ID:31889
资源大小:694.87KB
全文页数:3页
- 资源格式: PDF
下载:注册后免费下载
快捷下载

账号登录下载
微信登录下载
友情提示
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站资源下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。
5、试题试卷类文档,如果标题没有明确说明有答案则都视为没有答案,请知晓。
|
[20220207]IN11824_信息技术中的系统性漏洞——Log4Shell.pdf
1、CRS INSIGHT Prepared for Members and Committees of Congress INSIGHTINSIGHTi i Systemic Vulnerabilities in Information TechnologyLog4Shell Updated February 7, 2022 There is critical vulnerability in software used by millions of internet servers. Since its discovery both criminals and nation-state act
2、ors have reportedly exploited it. It is uncertain how many entities are vulnerable, but it is presumed there are many. This CRS Insight describes the vulnerability and federal government response considerations. Log4Shell Log4j is an open-source tool the Apache Foundation makes available for logging
3、 web server activity. To work, Log4J has to access many network services (e.g., network maps and directories). Malicious actors discovered a way to use the Log4j tool to send commands that give them control of the servers. The cybersecurity community named this vulnerability Log4Shell. Log4Shell exp
4、loits have been observed to mine cryptocurrencies and expand botnets. Apache Foundation software is very useful and freely available, so it is widely deployed. Hundreds of software projects maintained by the foundation rely on volunteer developers and are supported by donations and sponsorships. Res