The use of log4j2Scan.jar in reproducing log4j vulnerabilities

First install the plugin in burp
Insert image description here

After installation, the browser opens a website with a log4j vulnerability.
Insert image description here

There is no need to enable interception, the plug-in can automatically detect whether the website has log4j vulnerabilities.
Insert image description here

A + sign indicates that a vulnerability has been discovered

Guess you like

Origin blog.csdn.net/wutiangui/article/details/132734333