Ross ROSS = Recommend OSS · open-source software intelligence for agents

veracode-research/rogue-jndi

A malicious LDAP server for JNDI injection attacks observed · 2026-08-28

github.com/veracode-research/rogue-jndi · Java · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2485
  • days_rel: n/a
  • days_push: 1070
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1086 stars · 226 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Rogue JNDI is a malicious LDAP and HTTP server written in Java for exploiting insecure JNDI API usage in Java applications. It serves various payloads (remote classloading, unsafe reflection, XXE) to achieve remote code execution during penetration tests.

Use cases

  • test java applications for jndi injection vulnerabilities
  • demonstrate log4shell-style ldap exploitation in a pentest
  • simulate malicious ldap server for rce payloads
  • verify jndi lookup security fixes on tomcat or websphere
  • exploit insecure jndi remote classloading during authorized security assessment

When to choose

  • you are doing an authorized penetration test of a Java application with JNDI endpoints
  • you need ready-made payloads for Tomcat, Groovy, or WebSphere JNDI attack vectors
  • you want a lightweight single-jar tool to demonstrate JNDI injection risks

When to avoid

  • you need a general-purpose LDAP directory server
  • you lack authorization to test the target system
  • your target runs modern JDKs where remote classloading is disabled and no alternate payload applies

Facets

cli-tool · maturity maintenance

security http-server cli security penetration-testing developer-tools jvm cross-platform cli jndi-injection ldap-server exploitation rce log4shell penetration-testing java-security

1 source

Member repositories

RepositoryRoleHealth v2
veracode-research/rogue-jndimain32

For agents

markdown · JSON · MCP: product_card(name="veracode-research/rogue-jndi")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem