- Istio deployment & httpbin & sleep.
- Apply envoyfilter as below.
- Check requests and ensure they are denied as expected.
Pattern used in the config is found from https://github.com/avinetworks/datascript-library/blob/6740173e98e1ecfa72bdccc0650664d43d31e123/security/check_for_log4j_attacks.md
kex $(kpid sleep) -c sleep -- curl 'httpbin:8000/headers?foo=jndi'
kex $(kpid sleep) -c sleep -- curl 'httpbin:8000/ip' -H "Foo: Jndi"
kex $(kpid sleep) -c sleep -- curl 'httpbin:8000/ip' -H 'bar: ${${'