Log4Shell, explained: how one logged string became remote code execution
CVE-2021-44228 from first principles — what a JNDI lookup is, why Log4j evaluated one inside a log message, and the fixes that actually closed it.
root@0xpriv:~# id uid=0(root) gid=0(root) groups=0(root),1337(0xpriv),27(sudo) root@0xpriv:~# whoamiAlex Rowan Founder & Security Researcher at 0xpriv
root@0xpriv:~# cat bio.txt Founder of 0xpriv, covering offensive security, web application vulnerabilities, and practical security research through PHP, Python, and hands-on technical analysis. root@0xpriv:~# ls writeups/ | wc -l 2 root@0xpriv:~#
CVE-2021-44228 from first principles — what a JNDI lookup is, why Log4j evaluated one inside a log message, and the fixes that actually closed it.
A complete, hands-on Linux privilege escalation walkthrough: stabilise your shell, enumerate the host, and chain SUID, sudo, cron, capabilities and kernel flaws to reach root.