Log4Shell, explained: how one logged string became remote code execution
CVE-2021-44228 from first principles — what a JNDI lookup is, why Log4j evaluated one inside a log message, and the fixes that actually closed it.
How web applications break and how to fix them: injection, XSS, authentication and the browser security model.
CVE-2021-44228 from first principles — what a JNDI lookup is, why Log4j evaluated one inside a log message, and the fixes that actually closed it.