Oxeye Releases Ox4Shell
January 12, 2022

Oxeye unveiled an open-source initiative with the introduction of Ox4Shell.

The powerful and free open-source payload deobfuscation tool is in a series of solutions to be developed by Oxeye to assist developers, AppSec professionals, and the open-source community. Ox4Shell is designed to confront what some are calling the “Covid of the Internet,” known as the Log4Shell zero-day vulnerability. To counter a very effective obfuscation tactic used by malicious actors, Oxeye’s new open-source tool (available on GitHub) exposes hidden payloads which are actively being used to confuse security protection tools and security teams.

As reported by experts, organizations globally continue to experience remote code attacks and the exposure of sensitive data due to the pervasive Log4Shell vulnerability. Discovered in Apache’s Log4J, a logging system in widespread use by web and server application developers, the threat makes it possible to inject text into log messages or log message parameters, then into server logs which can then load code from a remote server for malicious use. Apache has given Log4Shell a CVSS severity rating of 10 out of 10, the highest possible score. Since then, researchers found a similar vulnerability in the popular H2 database. The exploit is simple to execute and is estimated to affect hundreds of millions of devices.

As part of a new open-source initiative for 2022, Oxeye is unveiling this in a series of contributions designed to strengthen security efforts by deobfuscating payloads often coupled with Log4J exploits. Ox4Shell exposes obscured payloads and transforms them into more meaningful forms to provide a clear understanding of what threat actors are trying to achieve, allowing the concerned parties to take immediate action and resolve the vulnerability.

The Log4j library has a few unique lookup functions that permit users to look up environment variables, Java process runtime information, and so forth. These enable threat actors to probe for specific information that can uniquely identify a compromised machine they’ve targeted. Ox4Shell enables you to comply with such lookup functions by feeding them mock data that you control.

“Difficulties in applying the required patching to the Log4Shell vulnerability means this exploit will leave gaps for malicious attacks now and in the future. The ability to apply obfuscation techniques to payloads, thereby circumventing the rules logic to bypass security measures also makes this a considerable challenge unless the proper remedy is applied,” said Daniel Abeles, Head of Research at Oxeye. Deobfuscation will be critical to understanding the true intention(s) of attackers. Ox4Shell provides a powerful solution to address this and as a supporter of the open-source community ...”

Share this

Industry News

January 26, 2022

Puppet announced a new competency-based global channel partner program for the company’s almost-200 worldwide channel partners that operate across 35 countries.

January 26, 2022

Weaveworks announced the acquisition of Magalix.

January 26, 2022

WhiteSource released an Azure DevOps repository integration, allowing Azure DevOps users to detect all open source components and automatically enforce security policies directly from their repository.

January 25, 2022

DataOps.live and Okera, the Universal Data Authorization company, announced a strategic partnership to increase the speed and security of sensitive data workloads running on the Snowflake Data Cloud Platform.

January 25, 2022

ConvergeOne released a Cyber Recovery as a Service (CRaaS) solution that utilizes innovative technologies from Dell Technologies and Amazon Web Services (AWS).

January 25, 2022

ArmorCode secured an additional $8 million in seed financing.

January 24, 2022

Oracle achieved FedRAMP High Provisional Authority to Operate (P-ATO) from the Joint Authorization Board (JAB) for an expanded set of Oracle Cloud Infrastructure (OCI) services.

January 24, 2022

Prophecy, the enterprise low-code data engineering platform that brings the speed of DevOps to data engineering, raised a $25 million Series A round.

January 20, 2022

Progress announced the R1 2022 release of Progress Telerik and Progress Kendo UI, powerful .NET and JavaScript UI libraries for app development.

January 20, 2022

CodeSee raised $7 million in additional funding, bringing the company’s raised total to $10 million.

January 20, 2022

Bugsnag now supports Unreal Engine by Epic Games used to develop 3D games, and Electron, a framework to build cross-platform desktop apps in JavaScript running on Windows, macOS, and Linux.

January 19, 2022

Dell Technologies introduced multi-cloud capabilities that offer a consistent experience wherever applications and data reside.

January 19, 2022

Harness announced that it is opening the CD component of its DevOps platform, which is now free and accessible under a source-available license, complementing its CI platform, which is already available under an open source license.

January 19, 2022

The latest offering from Plutora, the Test Environment QuickStart Bundle, takes an agile approach to evolving DevOps practices.

January 18, 2022

Appvance has secured $13 million in Series C funding to accelerate global expansion and product roadmap development.