Log4j: The pain just keeps going
thenewstack.io
Log4j: The pain just keeps going
1–10 of 291 posts
Re: Log4j: The pain just keeps going
#2Re: Log4j: The pain just keeps going
#3Re: Log4j: The pain just keeps going
#4As a small time hobby / small business server administrator (enthusiast) , what's the best practice here?
Re: Log4j: The pain just keeps going
#5Sometimes people ask me why I'm so skeptical about software delivery techniques involving bundling and static compilation. This is a thing that people sometimes ask.
Re: Log4j: The pain just keeps going
#6As a small time hobby / small business server administrator (enthusiast) , what's the best practice here?
https://owasp.org/www-project-dependency-check/
And some examples - https://jeremylong.github.io/DependencyCheck/dependency-chec...
Re: Log4j: The pain just keeps going
#7Re: Log4j: The pain just keeps going
#8It just seems like there's no solution. If Java is this bad imagine how much more attack surface a npm heavy project. Not only that the seeming hardware knowledge of state sponsored attackers seem sophisticated enough to gain access at the vendor level, which forces us to question even the most trusted methodologies and dependency management.
Re: Log4j: The pain just keeps going
#9As a small time hobby / small business server administrator (enthusiast) , what's the best practice here?
Re: Log4j: The pain just keeps going
#10As a small time hobby / small business server administrator (enthusiast) , what's the best practice here?
If vulnerable systems have no path to the internet at large then it's extremely difficult for attackers to know if a system is vulnerable to log4j and even harder to actually use it to exfiltrate data.