# wyzxxz/jndi_tool

JNDI服务利用工具 RMI/LDAP，支持部分场景回显、内存shell，高版本JDK场景下利用等，fastjson rce命令执行，log4j rce命令执行 漏洞检测辅助工具

Repository: https://github.com/wyzxxz/jndi_tool
Canonical: https://ross.abutalabs.com/products/jndi_tool
License Family: other
Last push: 2024-05-21T02:56:32+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2539, "days_push": 834, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2021, forks 318 (observed 2026-08-28T04:06:06.385909+00:00)

## What it is
A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, including high-JDK bypasses, fastjson and Log4j RCE, response echo, and memory shell injection. It is intended for authorized security testing and vulnerability verification.

## Use cases
- test jndi injection vulnerability in java app
- verify log4shell rce in my servers
- exploit fastjson deserialization rce
- bypass high jdk jndi restrictions
- detect which deserialization gadget chain works
- get command output echo from jndi rce
- inject memory shell via jndi

## When to choose
- you need an all-in-one JNDI/RMI/LDAP exploitation server for authorized pentests
- you need to test fastjson or Log4j RCE with payload tampering and auto gadget detection
- you need echo or memory shell capabilities in JNDI exploitation

## When to avoid
- you need a general-purpose vulnerability scanner rather than a targeted JNDI exploitation tool
- you lack authorization to test the target systems
- you need a maintained tool with a clear license and support

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, vulnerability-scanning, cli
- domain: security, penetration-testing, developer-tools
- platform: cli, jvm, cross-platform
- tags: jndi, rmi, ldap, log4shell, fastjson, rce, java-deserialization, exploitation, red-team, memory-shell

## Member repositories
- wyzxxz/jndi_tool (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:06.385909+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:00:12.680136+00:00, confidence not recorded.
  - readme: https://github.com/wyzxxz/jndi_tool (fetched 2026-08-28T04:06:06.385909+00:00, sha 715237b1097d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
