Fuzzing Java to Find Log4j Vulnerability - CVE-2021-45046
After the log4shell (CVE-2021-44228) vulnerability was patched with version 2.15, another CVE was filed. Apparently log4j was still vulnerable in some cases to a denial of service. However it turned out that on some systems, the issue can still lead to a remote code execution. In this video we use the Java fuzzer Jazzer to find a bypass. Jazzer Java Fuzzer: https://github.com/CodeIntelligenceTe... Anthony Weems: / amlweems 00:00 - Intro 00:54 - Chapter #1: The New CVE 03:38 - Chapter #2: Disable Lookups 05:43 - Chapter #3: Vulnerable log4j Configs 07:52 - Chapter #4: The Remote Code Execution 10:53 - Chapter #5: Parser Differential 12:57 - Chapter #6: Differential Fuzzing 16:07 - Chapter #7: macOS Only 18:15 - Chapter #8: Increase Impact 19:03 - Summary 19:58 - Outro =[ ❤️ Support ]= → per Video: / liveoverflow → per Month: / @liveoverflow =[ 🐕 Social ]= → Twitter: / liveoverflow → Instagram: / liveoverflow → Blog: https://liveoverflow.com/ → Subreddit: / liveoverflow → Facebook: / liveoverflow

Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

Log4J & JNDI Exploit: Why So Bad? - Computerphile

How To Protect Your Linux Server From Hackers!

Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)

Log4J Vulnerability (Log4Shell) Explained - for Java developers

I've been Hacking for 10 Years! (Stripe CTF Speedrun)

I Tried Every Major Linux Distro So You Don't Have To (Here's What I Found)

CVE-2021-44228 - Log4j - MINECRAFT VULNERABLE! (and SO MUCH MORE)

Something is jamming GPS over Europe. Here's what we found

How Netflix Uses Java - 2026 Edition

What is a Browser Security Sandbox?! (Learn to Hack Firefox)

How Huawei Just Built an Impossible Chip

START YOUR TUESDAY WITH FAITH | TODAY GOD IS GIVING YOU UNEXPECTED OPPORTUNITIES | FATHER FREDDY ...

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

A Vulnerability to Hack The World - CVE-2023-4863

How SUDO on Linux was HACKED! // CVE-2021-3156

"Something Wicked This Way Comes" — Why The AI Bubble Isn't What You Think

