Share this
DNSFilter Response to Log4j Vulnerability
by Arthur Chocholacek on Dec 13, 2021 12:00:00 AM
If you've been on the internet at all in the last 72 hours, you've undoubtedly heard that you should be concerned about the Log4j exploit and that lots of your software is currently vulnerable to it. On the off-chance you missed it, the nitty gritty details are here.
We've done a full internal audit of all aspects of the DNSFilter software stack, including our dashboard, backend software, databases, and our roaming clients, and can confidently say that we have no exposure to the log4j vulnerability from any angle.
Of course, we recommend doing a complete review of all of your software, as due to the nature of the exploit, it is not something DNSFilter can intercept and protect you from—but you don't have to worry about DNSFilter itself.
While DNSFilter does not play a role in mitigation or prevention of the Log4j threat, we do protect our users from malicious domains queried from your infrastructure. Since Log4j allows for the adding of malicious links into logs which get parsed, we can lessen the impact of these attacks if you are blocking malware, botnet, phishing, or other deceptive domains—including newly registered domains.
For assistance in discovering which tools actually use Log4j, this article from InfoWorld has some great suggestions on steps you can take.
Our very own Mikey Pruitt and Peter Lowe were on the RocketMSP podcast Monday December 13 discussing the Log4j vulnerability. (I made myself known in the background). You can watch the full video here:
Technical Update December 16, 2021:
As further CVEs have been released since our initial statement, we just wanted to follow up here to confirm that DNSFilter is not affected by any of the following CVEs related the the Log4J vulnerability. These include all CVEs currently known to us: CVE-2021-44228, CVE-2021-45046, CVE-2021-4104.
Full details of the vulnerabilities can be found on the CERT website.
Share this
Categories
- Featured (267)
- Protective DNS (23)
- IT (15)
- IndyCar (9)
- Content Filtering (8)
- Cybersecurity Brief (7)
- IT Challenges (7)
- Public Wi-Fi (7)
- AI (6)
- Deep Dive (6)
- Malware (4)
- Roaming Client (4)
- Team (4)
- Compare (3)
- MSP (3)
- Phishing (3)
- Tech (3)
- Anycast (2)
- Events (2)
- Machine Learning (2)
- Ransomware (2)
- Tech Stack (2)
- Secure Web Gateway (1)
Phishing attacks continue to be a prevalent threat to organizational security, exploiting human vulnerabilities rather than technical weaknesses. In fact, DNSFilter saw phishing attempts increase across our network by 203% YoY in 2024.
Every year at DNSFilter, we like to do our best to predict the future when it comes to cybersecurity. You might know this already if you’ve read the blog by our CTO, TK Keanini, about his 2025 cybersecurity predictions. We also like to review our predictions to see how well we did overall- it’s nice to keep score.
You lock your doors at night, secure your office, and ensure sensitive information is under strict control. But what if the biggest vulnerability in your business wasn't locked away at all? For most companies, their Domain Name System (DNS) is the gateway attackers are waiting for. It's a fundamental part of the internet's infrastructure, yet it's often ignored when it comes to security. Hackers know this, and they're taking advantage.