# welk1n/JNDI-Injection-Exploit

JNDI注入测试工具（A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc）

Repository: https://github.com/welk1n/JNDI-Injection-Exploit
Canonical: https://ross.abutalabs.com/products/jndi-injection-exploit
Language: Java
License: MIT
License Family: permissive
Last push: 2023-03-22T21:23:32+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2520, "days_push": 1260, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2823, forks 728 (observed 2026-08-28T04:07:24.106454+00:00)

## What it is
A Java-based penetration testing tool that generates workable JNDI links and starts RMI, LDAP, and HTTP servers to exploit JNDI injection vulnerabilities. It is used to test whether applications like those using Fastjson or Jackson are vulnerable to JNDI injection leading to remote code execution.

## Use cases
- generate jndi links for testing jndi injection vulnerabilities
- test fastjson deserialization rce poc
- test jackson jndi injection vulnerability
- start rmi and ldap servers for exploit delivery
- verify java application remote code execution via jndi lookup

## When to choose
- you need to test your own Java applications for JNDI injection vulnerabilities
- you want a ready-made tool to generate JNDI exploit links for POC validation
- you need RMI, LDAP, and HTTP servers bundled in one exploit tool

## When to avoid
- you need a general-purpose vulnerability scanner rather than a single-technique exploit tool
- your target is not a Java application using JNDI lookup
- you require ongoing support or frequent updates, as the project is in maintenance mode

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, penetration-testing, http-server, cli
- domain: security, penetration-testing, developer-tools
- platform: jvm, cli, cross-platform
- tags: jndi-injection, rmi-server, ldap-server, exploitation-tool, java-deserialization, vulnerability-testing

## Member repositories
- welk1n/JNDI-Injection-Exploit (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:24.106454+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:38:17.876829+00:00, confidence not recorded.
  - readme: https://github.com/welk1n/JNDI-Injection-Exploit (fetched 2026-08-28T04:07:24.106454+00:00, sha 0edb8dbfa15a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
