
PagerDuty’s Security Training for Engineers
Coding Blocks
00:00
The Top of Hacker News Ranow Is a Remote Control Execution Flaw With the Log for J T
This episode is, that'sori. Aha, so i literally the top of hacker news ranow is a remote control execution flaw with the log for j t. And what's funny about it is that it's an injection attack, where you can inject someceralized java objects and then, assuming that t the object is available in the class path, the logging framework will deceralize that into an object. It gets cerealized and does malicious stuff,. basel expiltrates either data or bagging, no back doors, back to the tackers, letting them run arbitrary codes.
Transcript
Play full episode