log4j-scan
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
Name:log4j-scan
Category:Vulnerabilities
Publisher:trickest-mhmdiaa
Created:2/5/2022
Container:
quay.io/trickest/log4j-scan:ceae24f
Output Type:
License:Unknown
Source:View Source
Parameters
-u
Check a single URL.-l
Check a list of URLs.--wait-time
Wait time after all URLs are processed (in seconds) - [Default: 5].--waf-bypass
Extend scans with WAF bypass payloads.--headers-file
Headers fuzzing list--run-all-tests
Run all available tests on each URL.--request-type
Request Type: (get, post) - [Default: get].--dns-callback-provider
DNS Callback provider (Options: dnslog.cn, interact.sh) - [Default: interact.sh].--custom-dns-callback-host
Custom DNS Callback Host.--exclude-user-agent-fuzzing
Exclude User-Agent header from fuzzing - useful to bypass weak checks on User-Agents.