Ross ROSS = Recommend OSS · open-source software intelligence for agents

wyzxxz/jndi_tool

JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具 observed · 2026-08-28

github.com/wyzxxz/jndi_tool observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2539
  • days_rel: n/a
  • days_push: 834
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2021 stars · 318 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, including high-JDK bypasses, fastjson and Log4j RCE, response echo, and memory shell injection. It is intended for authorized security testing and vulnerability verification.

Use cases

  • test jndi injection vulnerability in java app
  • verify log4shell rce in my servers
  • exploit fastjson deserialization rce
  • bypass high jdk jndi restrictions
  • detect which deserialization gadget chain works
  • get command output echo from jndi rce
  • inject memory shell via jndi

When to choose

  • you need an all-in-one JNDI/RMI/LDAP exploitation server for authorized pentests
  • you need to test fastjson or Log4j RCE with payload tampering and auto gadget detection
  • you need echo or memory shell capabilities in JNDI exploitation

When to avoid

  • you need a general-purpose vulnerability scanner rather than a targeted JNDI exploitation tool
  • you lack authorization to test the target systems
  • you need a maintained tool with a clear license and support

Facets

cli-tool · maturity active

security penetration-testing vulnerability-scanning cli security penetration-testing developer-tools cli jvm cross-platform jndi rmi ldap log4shell fastjson rce java-deserialization exploitation red-team memory-shell

1 source

Member repositories

RepositoryRoleHealth v2
wyzxxz/jndi_toolmain32

For agents

markdown · JSON · MCP: product_card(name="wyzxxz/jndi_tool")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem