Monday, July 4, 2022
Aroged
  • Home
  • World
  • Games
  • Technology
  • Sports
No Result
View All Result
  • Home
  • World
  • Games
  • Technology
  • Sports
No Result
View All Result
Aroged
No Result
View All Result
Home Technology

Researchers were able to initiate Log4Shell vulnerability by simply renaming iPhone and Tesla electric car

Aroged by Aroged
December 14, 2021
in Technology
0
Researchers were able to initiate Log4Shell vulnerability by simply renaming iPhone and Tesla electric car
0
SHARES
44
VIEWS
Share on FacebookShare on Twitter

Researchers were able to initiate a Log4Shell vulnerability by simply renaming the iPhone and Tesla electric car

Security researchers are continuing to investigate the new Log4Shell vulnerability that we discussed yesterday. Recall that it allows attackers to remotely execute code on vulnerable servers and inject malware that can completely compromise devices. The researchers found the vulnerability could be exploited on a variety of devices, including iPhones and Tesla electric vehicles.

As the screenshots show, by changing the name of an iPhone or Tesla device to a special exploit character string, it is possible to call a recall from Apple or Tesla servers. This indicates that the server is vulnerable to Log4Shell. After changing the device name, inbound traffic showed URL requests from IP addresses owned by Apple and China Unicom (Tesla’s Chinese mobile service partner). The researchers were able to trick Apple and Tesla’s servers into going to the URL they provided.

Researchers were able to initiate a Log4Shell vulnerability by simply renaming the iPhone and Tesla electric car

The Log4Shell vulnerability is dangerous in that it is relatively easy to exploit. It forces the application to interpret a piece of text as a link to a remote resource and try to access that resource. Although the system should only save the received text as a line in the application logs, and not follow the links. This makes many systems potentially vulnerable to accepting user input. For example, these can be the systems of SMS providers.

In theory, an attacker could place malicious code at the target URL in order to infect vulnerable servers. However, a well-maintained network can prevent such an attack at the network layer. Thus, more broadly, there is no indication that this method could significantly compromise Apple or Tesla systems. None of the companies responded to requests from The Verge to comment on this information.

It is not yet known whether the attackers actually managed to compromise any systems using the Log4Shell vulnerability. However, the Cado platform has reported that servers have already been found trying to use this method to install the Mirai botnet code.

An update to the log4j-2.15.0-rc2 library has already been released to fix the Log4Shell vulnerability.

A source: The Verge


Tags: carelectricinitiateiPhoneLog4ShellrenamingResearcherssimplyTeslavulnerability

Related Posts

Apple was unable to return employees from remote to offices due to a new outbreak of COVID-19 in the United States
Technology

Apple was unable to return employees from remote to offices due to a new outbreak of COVID-19 in the United States

by Aroged
July 4, 2022
Asus ROG Phone 6 official press images leaked before presentation
Technology

Asus ROG Phone 6 official press images leaked before presentation

by Aroged
July 3, 2022
WhatsApp will allow you to hide your online status from all users
Technology

WhatsApp will allow you to hide your online status from all users

by Aroged
July 3, 2022
Xiaomi Band 7 Pro will receive the Always On Display function
Technology

Xiaomi Band 7 Pro will receive the Always On Display function

by Aroged
July 3, 2022
TikTok confirms that some employees of the social network from China could access the data of users from the United States
Technology

TikTok confirms that some employees of the social network from China could access the data of users from the United States

by Aroged
July 3, 2022
Next Post
Will Macko Esports dominate Rainbow Six Siege in 2022 too?

Will Macko Esports dominate Rainbow Six Siege in 2022 too?

Xiaomi: More MIUI 13 revelations now released (video)

Xiaomi: More MIUI 13 revelations now released (video)

Intel chief arrives in Taiwan for talks with TSMC last night

Intel chief arrives in Taiwan for talks with TSMC last night

Browse by Tags

Action AMD announced Apple Aroged chip Coming date developers Elden free game Gameplay Games GeForce Intel launch Microsoft million news Nintendo NVIDIA Online Pass play Players Playstation Pro PS5 release released Ring Russia Season Series Steam Store Switch trailer update video War World Xbox year
Aroged

News Around World And News About Business, Entertainmen, Fashion, Food, Games News, Health, PC Portables, Telecomtalk, Sports, Make Money Online and more all on one platform.

Categories

  • Games
  • India
  • Sports
  • Technology

Browse by Tag

Action AMD announced Apple Aroged chip Coming date developers Elden free game Gameplay Games GeForce Intel launch Microsoft million news Nintendo NVIDIA Online Pass play Players Playstation Pro PS5 release released Ring Russia Season Series Steam Store Switch trailer update video War World Xbox year

Recent Posts

  • Al-Haytham in Genshin Impact: appearance, elements and weapons of the new character
  • Meizu completed the transition under the control of the automotive company Geely
  • The Silent Hill PS5 teaser is completely fake for Dusk Golem
  • About Us
  • Home
  • Terms of use

© Aroged 2022. All Rights Reserved.

No Result
View All Result
  • Home
  • World
  • Games
  • Technology
  • Sports

© Aroged 2022. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.