Hacker News new | ask | show | jobs
by mosajjal 1659 days ago
this Snort signature should detect it fairly reliably:

alert tcp -> ( msg:"log4j rce detection"; content:"|24 7b|jndi|3a|"; nocase; )