Log4j batch file execution

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Log4j batch file execution

L2 Linker

Hi All.

 

From the Palo alto advisory as per below, we have to run a batch file via our SCCM tool. But I need to understand what version of log4j we are using on our Cortex. How can we find out , Please help

 

To ensure you disable message lookup, follow the following steps:

  1. Disable Log4j message lookups environment variable
    • XDR Pro customers - From the Action Center, select Actions > Run Endpoint Script and in the SCRIPT field select execute_command. Specify the Commands_lists(list) field as setx LOG4J_FORMAT_MSG_NO_LOOKUPS true /M. In the next screen, you will have an option to select the target machines.
    • XDR Prevent customers - Execute the following batch script with administrative privileges on your machines: https://storage.cloud.google.com/panwxdr-staticfiles/apply_log4shell_workaround.bat
3 REPLIES 3

L5 Sessionator

Hi @AsifSid , You're the best person to know what is running in your environments. You can run a XQL query to partially identify if the vulnerable JAR's are being loaded or if JNDI calls are being made in your estate.

 

This should get you started on the right track: https://www.paloaltonetworks.com/blog/security-operations/hunting-for-log4j-cve-2021-44228-log4shell....

L0 Member

The link asks us to log into a google account. We're a Microsoft shop, is there anywhere else we can download the file from?

@Victor1 It is a publicly available link. Are you able to view the link from your mobile or another device?

  • 2322 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!