meta_pixel
Tapesearch Logo
Log in
Tech Brew Ride Home

Mon. 12/13 – Why the Log4j Bug Is Such A Big Deal

Tech Brew Ride Home

Amalgamated Internets, LLC

Tech News, News, Technology

4.71K Ratings

🗓️ 13 December 2021

⏱️ 20 minutes

🧾️ Download transcript

Summary

A huge bug in Apache servers is causing chaos around the Internet. What to expect, and what we’re still waiting on from iOS 15.2. Why did Instagram steal the @metaverse handle from a woman in Australia, and the story of the fat finger fire sale of a Board Ape Yacht Club NFT. Sponsors: Grammarly.com/techmeme Tovala.com/ride Links: Zero-day in ubiquitous Log4j tool poses a grave threat to the Internet (ArsTechnica) The Internet’s biggest players are all affected by critical Log4Shell 0-day (ArsTechnica) PROFESSIONAL MAINTAINERS: A WAKE-UP CALL (Filippo.io) Apple Set to Release Nudity Detection in Texting, But Other Features Remain on Hold (Bloomberg) Her Instagram Handle Was ‘Metaverse.’ Last Month, It Vanished. (NYTimes) Bored Ape Yacht Club: Someone accidentally sold a $300,000 NFT for $3,000 (CNET) Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

Welcome to the Tech Meme Ride Home for Monday, December 13th, 2021. I'm Brian McCullough today.

0:09.0

A huge bug in Apache servers is causing chaos around the internet, what to expect and what

0:14.6

we're still waiting on from iOS 15.2. Why did Instagram steal the

0:20.0

at metaverse handle from a woman in Australia and the story of the Fat Finger Fire

0:24.7

sale of a board ape yacht club NFT. Here's what you miss today in the world of

0:29.8

Tech. Really bad news over the week. tech.

0:41.0

Really bad news over the weekend, a vulnerability in the Apache Log4J Java Logging Library was discovered that allows for remote code execution and

0:45.0

impacting everything from steam to iCloud to Minecraft and all sorts of services.

0:49.7

In fact, this was first discovered by Minecraft users and look it basically affects everything

0:55.9

I've even heard tour servers are being unmasked quoting Arse Technica word of the vulnerability first came to light on sites catering to users of Minecraft the best-selling

1:06.4

game of all time.

1:07.8

The sites warned that hackers could execute malicious code on servers or clients running the

1:12.0

Java version of Minecraft by manipulating log messages

1:15.1

including from things typed in chat messages.

1:18.3

The picture became more dire still as Log 4J was identified as the source of the vulnerability and exploit code was discovered

1:25.5

posted online. Log 4J is incorporated into a host of popular frameworks including Apache Struts 2, Apache Solar, Apache Druid, and Apache

1:35.6

Flink, that means a dizzying number of third-party apps may also be vulnerable to exploits

1:40.6

of the same high severity as those threatening

1:43.2

Minecraft users.

1:44.8

Researchers said the Java desirialization bug

1:48.1

stems from Log 4J making network requests

1:51.5

through the JNDI to an LDAP server and executing any code that's

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Amalgamated Internets, LLC, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Amalgamated Internets, LLC and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.