Contact us: info@tenendo.com
JNDI injection. Log4Shell case study
On December 10, 2021, Apache released a fix for CVE-2021-44228, a critical RCE vulnerability affecting Log4j that is being exploited in the wild.
A technical blog focused on application and infrastructure security, with insights into secure coding practices, adversary simulation, and advanced penetration testing techniques.
We cover topics such as web and mobile application testing, especially within the fintech and banking sectors, as well as social engineering tactics, initial access techniques, and the development of custom malware, evasion methods, and command-and-control (C2) frameworks.