Crossing the Log4j Horizon - A Vulnerability With No Return

In this article, we are going to exploit Log4j vulnerabilities in VMWare Horizon, get a reverse shell, and leverage our access to add a backdoor to the VMBlastSG framework. We have also made available a GitHub repository that automates the exploitation process.


Another Log4j on the fire: Unifi

By now, you’re probably well aware of a recently disclosed vulnerability for the Java logging library, Log4j. The vulnerability is wide-reaching and affects Ubiquiti's Unifi Network Application.

In this article, we’re going to break down the exploitation process and touch on some post-exploitation methods for leveraging access to the underlying operating system.