What your netflows, pflow, whatever logging system you have show on port 389, 636 in the last 4 days?
If you reply nothing... I will admit my mistake here publicly. I will be happy to be wrong in your face. Jean -----Original Message----- From: Saku Ytti <[email protected]> Sent: December 13, 2021 6:33 AM To: Jean St-Laurent <[email protected]> Cc: Jörg Kost <[email protected]>; [email protected] Subject: Re: Log4j mitigation On Mon, 13 Dec 2021 at 13:31, Jean St-Laurent <[email protected]> wrote: > It's possible to see it live crawling in your network. Why let something > harmful continue to crawl and spread? My apologies, I missed this part. How? -- ++ytti

