Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Server responses not getting to internal interact.sh server. #120

Open
nitchimon opened this issue Jan 4, 2022 · 0 comments
Open

Server responses not getting to internal interact.sh server. #120

nitchimon opened this issue Jan 4, 2022 · 0 comments

Comments

@nitchimon
Copy link

nitchimon commented Jan 4, 2022

we're sending through log4j-scan.py a custom dns callback host and we are not seeing anything being returned to the internal interact.sh server.

We cleared all network roadblocks internal, but the server hit, known to be vulnerable, just does DNS queries.

We dug into this and discovered that the server being hit is trying to find via DNS the beginning of the test, not the URL or IP of the callback host.

Example: DNS query on ${jnd:${upper.nsnew.test.com , or $jndi.nsnew.test.com
Basically it is looking for the beginning of the test for dns NOT the passed callback host.

Anyone have any ideas why this is happening ?
DNS resolves nsnew.test.com perfectly.

This happens if I pass the callback host as an IP, FQDN, or http://ip or http://fqdn

any thoughts ?

thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant