# The Log4j vulnerability : what response have you seen?

**URL:** <https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040>\
**Category:** In My Humble Opinion\
**Created:** [December 14, 2021, 11:11am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040 "2021-12-14T11:11:43Z")\
**Posts on this page:** 12\
**Page:** 2

<div class="post-metadata">

**Author:** ![Sage\_Rat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sage_rat/32/399_2.png) [@Sage\_Rat](https://boards.straightdope.com/u/Sage_Rat)\
**Post date:** [December 14, 2021, 5:54pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/21 "2021-12-14T17:54:02Z")

</div>

> [@BigT](#):
>
> Java is popular on routers and modems? That just seems so odd to me. The ones I’ve seen always seemed like they were running some version of Linux with a custom shell, with a very basic webserver. Running Java on top of that would seem inefficient.

I don’t know how popular it is but Java ME came out something like 20 years ago and could run on devices like pagers and pocket dictionaries, just fine. I would assume that modern routers are at or above that level of hardware by this point.

Ultimately, there aren’t that many people who can code C and C++ at all, let alone write optimal C/C++ code. It’s cheaper and easier for most companies to have one or two low-level engineers who get the platform running, and put ME on top of it. After that’s done, you can hand it over to some 18 year old that can barely implement fizz-buzz, and let him code whatever all else the business wants in Java.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 14, 2021, 10:36pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/22 "2021-12-14T22:36:55Z")

</div>

Java ME is what I was talking about with the cell phones. I guess that makes sense.

But the hardware I’ve had definitely seems underpowered. The webserver for one would timeout like crazy if the router was doing anything else. And, as I said, the new one is just incredibly slow. It just seems to me like it would make more sense to use “off the shelf” open source web severs that were already built in lower level languages.

---

<div class="post-metadata">

**Author:** ![N9IWP](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/n9iwp/32/3154_2.png) [@N9IWP](https://boards.straightdope.com/u/N9IWP)\
**Post date:** [December 15, 2021, 11:59am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/23 "2021-12-15T11:59:54Z")

</div>

Lots of scrambling at work – luckily none of the code I am responsible for uses log4j. One of the pieces is on top of something that uses log4j, but not the vulnerable version.

Brian

---

<div class="post-metadata">

**Author:** ![FinsToTheLeft](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/finstotheleft/32/2930_2.png) [@FinsToTheLeft](https://boards.straightdope.com/u/FinsToTheLeft)\
**Post date:** [December 15, 2021, 5:47pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/24 "2021-12-15T17:47:57Z")

</div>

I now have customers yelling about Azure services being vulnerable even though both Microsoft and Databricks say the aren’t vulnerable and being PaaS, we have no ability to remediate or even confirm if Log4J is in the underlying distro. Microsoft has a very small list of potentially vulnerable services, but not with the clients in question.

---

<div class="post-metadata">

**Author:** ![TheGunIsMightierThanThePen](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/thegunismightierthanthepen/32/2981_2.png) [@TheGunIsMightierThanThePen](https://boards.straightdope.com/u/TheGunIsMightierThanThePen)\
**Post date:** [December 17, 2021, 6:16am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/25 "2021-12-17T06:16:11Z")

</div>

Multiple internal tools that my company uses were found to have vulnerabilities from Log4j, but fortunately the application I directly work on is not one of them. However, the repository that holds my team’s code, as well as another platform that hosts our compiled code modules and other libraries our code depends upon, were found to be affected, and other teams are actively working on patching them as we speak.

---

<div class="post-metadata">

**Author:** ![Unintentionally\_Blank](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/unintentionally_blank/32/5418_2.png) [@Unintentionally\_Blank](https://boards.straightdope.com/u/Unintentionally_Blank)\
**Post date:** [December 17, 2021, 7:41pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/26 "2021-12-17T19:41:08Z")

</div>

> [@Heracles](#):
>
> Well, basically, it’s a security hole that may affect server-based software and especially websites, if they are built using a certain set of tools and use some versions of a library called Log4j. Log4j is used for logging (writing technical logs about event sequences), and it costs nothing to use, so it’s included for troubleshooting purposes in many pieces of software.

That’s mostly correct. It’s just the internet facing systems that use Java and this library are most immediately susceptible to attack…

But really _any_ java based application using the library has a severe chink in their armor…which could extend to anything else on a machine, if it were compromised, and the attacker elevated their privilege on that machine. Logging is a pretty common requirement for applications.

For us, it’s been a week of patching…only to get another email from a vendor saying ‘the first remediation may not be quite enough.’

---

<div class="post-metadata">

**Author:** ![DCnDC](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dcndc/32/2842_2.png) [@DCnDC](https://boards.straightdope.com/u/DCnDC)\
**Post date:** [December 17, 2021, 7:45pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/27 "2021-12-17T19:45:51Z")

</div>

I got an email from my organization earlier this week stating that none of our systems were at risk.

---

<div class="post-metadata">

**Author:** ![Zakalwe](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/zakalwe/32/270_2.png) [@Zakalwe](https://boards.straightdope.com/u/Zakalwe)\
**Post date:** [December 18, 2021, 1:20am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/28 "2021-12-18T01:20:59Z")

</div>

We’re a huge Java shop.

67+ applications based on 27 or so internal libraries all impacted - plus about 15 or so purchased and installed applications (including ESRI ArcGIS Enterprise). Senior programmers working insane hours since last Friday, emergency deployments, etc.

Our frigging kickstarter had Log4j included. That has now been remediated.

Yeah, it’s a big deal. The best analogy I’ve seen is that someone gives your housekeeper a big sealed box. They bring the box into your house and open it with no clue what’s inside.

---

<div class="post-metadata">

**Author:** ![si\_blakely](https://avatars.discourse-cdn.com/v4/letter/s/d9b06d/32.png) [@si\_blakely](https://boards.straightdope.com/u/si_blakely)\
**Post date:** [December 27, 2021, 2:21am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/29 "2021-12-27T02:21:20Z")

</div>

I just saw some logs from a customer where the log4j attack was being thrown at **sshd** in the hopes that sshd was logging via log4j (it wasn’t).

This is just another instance of not correctly handling uncontrolled data, but it also illustrates how poorly many sites manage network security - there should be no reason for a webserver inside your network to be allowed to make arbitrary ldap connections to the internet, and not having a robust firewall policy to prevent that is negligent, in my opinion.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [December 27, 2021, 7:32am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/30 "2021-12-27T07:32:54Z")

</div>

What a blusterschmuck! This is proving to be the catastrophe that Y2K was supposed to be!

---

<div class="post-metadata">

**Author:** ![JohnT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnt/32/15048_2.png) [@JohnT](https://boards.straightdope.com/u/JohnT)\
**Post date:** [December 27, 2021, 11:37am UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/31 "2021-12-27T11:37:37Z")

</div>

> [@FinsToTheLeft](#):
>
> > [@Broomstick](#):
> >
> > I don’t think my home router is internet accessible, but how do I find out for sure? How would I find out if my firewall uses the bad log4j?
> 
> Just Google [Router Manufacturer] [Model] Log4J, and see if your router manufacturer has published updated firmware. If so, you should see instructions to download and update the firmware.

Thank you for this. Appreciate it, **Fins**.

---

<div class="post-metadata">

**Author:** ![Projammer](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/projammer/32/559_2.png) [@Projammer](https://boards.straightdope.com/u/Projammer)\
**Post date:** [December 29, 2021, 5:14pm UTC](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040/32 "2021-12-29T17:14:18Z")

</div>

The easiest way to check/test is to log into your router, go to the admin page and check for firmware upgrades. If there is one, install it. That would be your solution if your router were vulnerable and staying current with firmware is generally considered a best practices operation in any event.

ETA: We got an FYSA email last week that several hundred servers/apps were patched and monitoring is ongoing for anything that was overlooked. Not within my scope of responsibilities so no details. Just reassuring me so I can reassure anyone who asks.

[Previous page](https://boards.straightdope.com/t/the-log4j-vulnerability-what-response-have-you-seen/956040.md?page=1)
