A Detailed Guide on Log4J Penetration Testing


Oh boy you should hear what the CEO of apache said in an interview today, Basically, he said the following:

He stated that the log4j isn't a program error persé but more a setting problem. After that he said: There should be more safety lines in place in our software. We first off wanted to keep this leak quiet until we had a fix for it, we then realized that we couldn't do this for our users that they become vulnerable to this kind of exploit. You do not want your software supplier to keep such things secret true juridical tricks.

Also, he said that de experience of commercial cybersecurity experts is not ideal or even not efficient enough. There should be more lifelines in place in our software. If you try to disable a security setting it should not ask: 'do you want to disable this' Yes or no instead it should say the following: 'do you want to disable this' Yes because I am an idiot' or no.

After that, he claimed that software should be made untrusted by nature. "Apache is still used by banks, those banks have a competent security department. In those security departments, you see that security is been sold off to the cheapest option.

This must be a wake-up call for the world, after that the world would be better too.

Link to the article: https://www.security.nl/posting/734885/Apache-oprichter%3A+we+moeten+software+van+nature+wantrouwiger+maken Mind you it is in Dutch.

Edit: Dirk-Willem van Gulik was intervied. This is the current founder and first president of the apache software foundation.

