H0NEY4LOG
Sujatha Gurunathan · Advances in information security, privacy, and ethics book series · 2025
Nowadays, most Java- based applications use the log4j framework because it is a quick and framework which is dependable that is entirely written in programming language Java to have a log of all the information that takes place in the application. The Apache Software License, governs the log4j package, making it widely available for use and modification to suit individual needs. Due to wide usage of API, this particular utility of Java was exploited to malignantly initiate RCE that executes set of commands that puts data of the user at danger of getting it stolen and malignant intent. The IoT devices are at danger since the Log4j vulnerability is so simple to attack. The proposed system with honeypot requires little input and, in addition to alerting the relevant team, contains an internal scanner that can determine whether a specific website is susceptible to the log4jshell vulnerability. It also recognizes and warns of SSH-based threats. On top of a secure system, this scanner and the honeypot add another degree of security.