Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228 @LiveOverflow
Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228  @LiveOverflow
Uploaded December 2021 | Updated September 2026, 2 weeks ago
Let's try to make sense of the Log4j vulnerability called Log4Shell. First we look at the Log4j features and JNDI, and then we explore the history of the recent log4shell vulnerability. This is part 1 of a two part series into log4j.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-0day/java-hacking
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Log4j Issues:
2013: issues.apache.org/jira/browse/LOG4J2-313
2014: issues.apache.org/jira/browse/LOG4J2-905
2017: issues.apache.org/jira/browse/LOG4J2-2109

Log4j 2 Security: logging.apache.org/log4j/2.x/security.html

German Government Warning: bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2021/2021-549032-10F2.pdf?__blob=publicationFile&v=3

Cloudflare: blog.cloudflare.com/exploitation-of-cve-2021-44228-before-public-disclosure-and-evolution-of-waf-evasion-patterns

A JOURNEY FROM JNDI/LDAP
MANIPULATION TO REMOTE CODE
EXECUTION DREAM LAND: blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf
whitepaper: blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf

---

CHAPTERS
00:00 - Intro
01:05 - BugBounty Public Service Announcement
02:23 - Chapter #1: Log4j 2
03:38 - Log4j Lookups
04:15 - Chapter #2: JNDI
06:01 - JNDI vs. Log4j
06:35 - Chapter #3: Log4Shell Timeline
07:33 - Developer Experiences Unexpected Lookups
09:51 - The Discovery of Log4Shell in 2021
11:08 - Chapter #4: The 2016 JNDI Security Research
11:56 - Java Serialized Object Features
13:27 - Why Was The Security Research Ignored?
14:44 - Chapter #5: Security Research vs. Software Engineering
16:49 - Final Words and Outlook to Part 2
17:23 - Outro

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#GameHacking #SecurityResearch #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228Defusing a Bomb at Google London HQ - Having a Blast Google CTF Finals 2019 (hardware)Do you know this common Go vulnerability?Does Hacking Require Programming Skills?Security-driven Rapid Release - Pwn2Own Documentary (Part 4)How The RIDL CPU Vulnerability Was FoundFinding Player and Camera Position for Fly Hack - Pwn Adventure 3Learn Fault Injection at DEF CON 2026Finding 0day in Apache APISIX During CTF (CVE-2022-24112)My Life in Short/Shirt Stories - The Time I Learned PenSpinning (~2007-2009) - Shirt Stories #1Hacking My Instagram AccountUnderstanding C Pointer Magic Arithmetic | Ep. 07
LiveOverflow |

Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER