# Delete JndiLookup.class

**URL:** <https://discuss.elastic.co/t/delete-jndilookup-class/291507>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [December 11, 2021, 1:23pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507 "2021-12-11T13:23:14Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 11, 2021, 1:23pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/1 "2021-12-11T13:23:14Z")

</div>

Dear Team,

I am unable to find the file  
zip -q -d \<LOGSTASH\_HOME\>/logstash-core/lib/jars/log4j-core-2.\* org/apache/logging/log4j/core/lookup/JndiLookup.class

Can someone please help me or guide me.

Regards

---

<div class="post-metadata">

**Author:** ![X11](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/x11/32/98759_2.png) [@X11](https://discuss.elastic.co/u/X11)\
**Post date:** [December 12, 2021, 2:35am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/2 "2021-12-12T02:35:57Z")

</div>

if you have logstash running on a linux server should be in

`/usr/share/logstash/logstash-core/lib/jars/`

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 12, 2021, 2:48am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/3 "2021-12-12T02:48:36Z")

</div>

Hi @X11 ,

Thankyou for the response.  
I can find the jars in the location  
-d \<LOGSTASH\_HOME\>/logstash-core/lib/jars/log4j-core-2.\*

But what about the path

org/apache/logging/log4j/core/lookup/JndiLookup.class

Regards

---

<div class="post-metadata">

**Author:** ![fanboy1234](https://avatars.discourse-cdn.com/v4/letter/f/ce73a5/32.png) [@fanboy1234](https://discuss.elastic.co/u/fanboy1234)\
**Post date:** [December 12, 2021, 2:56am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/4 "2021-12-12T02:56:46Z")

</div>

If the logstash is run as Docker container then how do we delete jndilookup class. Please throw some light

---

<div class="post-metadata">

**Author:** ![X11](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/x11/32/98759_2.png) [@X11](https://discuss.elastic.co/u/X11)\
**Post date:** [December 12, 2021, 5:45am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/5 "2021-12-12T05:45:44Z")

</div>

The .class file is the class you’re deleting from the jar file ; if you copied that .jar file to /tmp and ran unzip on it, you’d see all the Java classes that make up the jar…

I would think it’s same location in docker, so the first thing I would do, w/out a ton of docker experience, is basically add the same command to my Dockerfile, build the image and test it out… it’s pretty arbitrary to test, I could trigger outbound ldap (389/tcp) with this logstash config

```auto
input {
    tcp { 
        port => 1337
        codec => json 
    }
output { 
—- SNIP —-

```

then send a message to ther listener with the common payload going around; if you’re doing it in bash you have to escape the “$”, at least that’s what worked for me. Mods sorry in advance for the dns names in the screenshots

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/1/41561d2be4d323c7cf9dc6f19da41f2dec920834.jpeg)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5cf4448907e972378a9a9338c00d006aa0bc5de.jpeg)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c1cf6a2ecab891ba602d0775fcce747d8ef97a2a.jpeg)

---

<div class="post-metadata">

**Author:** ![Kami](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kami/32/98757_2.png) [@Kami](https://discuss.elastic.co/u/Kami)\
**Post date:** [December 12, 2021, 12:10pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/6 "2021-12-12T12:10:22Z")

</div>

Here is a workaround / temporary mitigation I'm using from another thread which utilizes a Dockerfile - [Zero-day-exploit in log4j2 which is part of elasticsearch - #35 by Kami](https://discuss.elastic.co/t/zero-day-exploit-in-log4j2-which-is-part-of-elasticsearch/291439/35).

Keep in mind that glob expansion approach didn't work for me so I use full absolute path - make sure the full path is the same in your case (it may be different with older logstash versions, but I didn't dig in).

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 13, 2021, 5:07am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/7 "2021-12-13T05:07:13Z")

</div>

Hello @Kami ,

Can you please let me know the path Jndilookup.class in the jar file.  
since losgstash home is /usr/share/logstash.

your help would be much appreciated.

Regards

---

<div class="post-metadata">

**Author:** ![Kami](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kami/32/98757_2.png) [@Kami](https://discuss.elastic.co/u/Kami)\
**Post date:** [December 13, 2021, 9:36am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/8 "2021-12-13T09:36:30Z")

</div>

It may be different in your deployment and logstash version.

You should use "jar" command to find out the path for that class.

```auto
jar tf /opt/logstash/logstash-core/lib/jars/log4j-core-2.14.0.jar | grep -i jndi

```

You should of course replace "/opt/logstash/logstash-core/lib/jars/log4j-core-2.14.0.jar" with a path to the jar file in your setup (`find /usr/share/logstash -name "log4*core*.jar`).

---

<div class="post-metadata">

**Author:** ![zanoob](https://avatars.discourse-cdn.com/v4/letter/z/a6a055/32.png) [@zanoob](https://discuss.elastic.co/u/zanoob)\
**Post date:** [December 14, 2021, 12:27pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/9 "2021-12-14T12:27:41Z")

</div>

> [@Kami](#):
>
> ould use "jar" command to find out the path for that class

I was able to find the Jndilookup.class from that command as shown below:

jar tf /usr/share/logstash/logstash-core/lib/jars/log4j-core-2.13.3.jar | grep -i jndi  
org/apache/logging/log4j/core/selector/JndiContextSelector.class  
org/apache/logging/log4j/core/lookup/JndiLookup.class  
org/apache/logging/log4j/core/net/JndiManager$1.class  
org/apache/logging/log4j/core/net/JndiManager.class  
org/apache/logging/log4j/core/net/JndiManager$JndiManagerFactory.class  
org/apache/logging/log4j/core/util/JndiCloser.class

and tried to delete it using the command (where /usr/share/logstash is my home directory for logstash)

zip -q -d /usr/share/logstash/logstash-core/lib/jars/log4j-core-2.\* org/apache/logging/log4j/core/lookup/JndiLookup.class

-bash: zip: command not found

Regards,  
Zanoob

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 14, 2021, 7:46pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/10 "2021-12-14T19:46:50Z")

</div>

If you are using `bash` and the ` **/*` does _** NOT**_ work, then run `shopt -s globstar` before running the `zip` command.

```auto
shopt -s globstar
ls -lrt /usr/share/logstash/logstash-core/**/*/log4j-core-2.*

```

```auto
zip -d <output_of_above_command> org/apache/logging/log4j/core/lookup/JndiLookup.class
chown logstash:logstash <output_of_above_command>

```

Restart Logstash.

---

<div class="post-metadata">

**Author:** ![shrikantgulia](https://avatars.discourse-cdn.com/v4/letter/s/c68b51/32.png) [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Post date:** [December 16, 2021, 5:38am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/11 "2021-12-16T05:38:28Z")

</div>

thankyou people.

Regards  
Shrikant

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [December 16, 2021, 10:31pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/12 "2021-12-16T22:31:47Z")

</div>

Do you know how to remove the class for the Jar file on windows side besides copying the file over to Linux to remove the class file? I tried opening the file w/ 7-zip to delete the class file but that didn't work. Wonder if it's possible to extract, delete, and rearchive.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 17, 2021, 6:04am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/13 "2021-12-17T06:04:46Z")

</div>

you should be able to use equivalent windows command-line zip tools. I remember seeing a post that someone did it on windows but cannot recollect.

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [December 21, 2021, 6:42am UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/14 "2021-12-21T06:42:10Z")

</div>

Elastic has come out with a removal tool and an excellent article on Logstash that should clarify all the doubts - [Logstash 5.0.0-6.8.20 and 7.0.0-7.16.0: Log4j CVE-2021-44228, CVE-2021-45046 remediation](https://discuss.elastic.co/t/logstash-5-0-0-6-8-20-and-7-0-0-7-16-0-log4j-cve-2021-44228-cve-2021-45046-remediation/292343)

---

<div class="post-metadata">

**Author:** ![zanoob](https://avatars.discourse-cdn.com/v4/letter/z/a6a055/32.png) [@zanoob](https://discuss.elastic.co/u/zanoob)\
**Post date:** [January 3, 2022, 1:46pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/15 "2022-01-03T13:46:47Z")

</div>

> [@sandeepkanabar](#):
>
> `ls -lrt /usr/share/logstash/logstash-core/**/*/log4j-core-2.*`

Hello Sandeep,

Thank you for the reply, I ran the command  
shopt -s globstar  
ls -lrt /usr/share/logstash/logstash-core/\*\*/_/log4j-core-2._

Since you mentioned \*_/_ does not run from bash and then I tried to runt the zip file, but still getting an error.

[root@serverlogstash jars]# shopt -s globstar  
[root@serverlogstash jars]# ls -lrt /usr/share/logstash/logstash-core/\*\*/_/log4j-core-2._  
-rw-r--r--. 1 logstash logstash 1714164 Mar 18 2021 /usr/share/logstash/logstash-core/lib/jars/log4j-core-2.13.3.jar  
[root@serverlogstash jars]#  
[root@serverlogstash jars]# zip -d /usr/share/logstash/logstash-core/lib/jars/log4j-core-2.13.3.jar org/apache/logging/log4j/core/lookup/JndiLookup.classchown logstash:logstash /usr/share/logstash/logstash-core/lib/jars/log4j-core-2.13.3.jar  
-bash: zip: command not found  
[root@serverlogstash jars]# pwd  
/usr/share/logstash/logstash-core/lib/jars  
[root@serverlogstash jars]#

Regards,  
Zanoob

---

<div class="post-metadata">

**Author:** ![sandeepkanabar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandeepkanabar/32/79399_2.png) [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Post date:** [January 3, 2022, 4:53pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/16 "2022-01-03T16:53:32Z")

</div>

> [@zanoob](#):
>
> -bash: zip: command not found

Looks like `zip` is not installed in your machine. Please install the `zip` utility and then re-run

---

<div class="post-metadata">

**Author:** ![zanoob](https://avatars.discourse-cdn.com/v4/letter/z/a6a055/32.png) [@zanoob](https://discuss.elastic.co/u/zanoob)\
**Post date:** [January 4, 2022, 2:49pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/17 "2022-01-04T14:49:58Z")

</div>

That worked .  
Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2022, 2:50pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507/18 "2022-02-01T14:50:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
