Web Hack List

Later archive addition

A Journey from JNDI/LDAP Manipulation to Remote Code Execution Dream Land

When a Java application performs a JNDI lookup on an attacker-controlled name, the attacker serves a naming reference over RMI, CORBA or LDAP that makes the victim fetch and instantiate a remote factory class, giving code execution. A poisoned LDAP directory entry achieves the same against applications that merely search it.

Record

Researcher
Alvaro Muñoz and Oleksandr Mirosh
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alvaro Muñoz and Oleksandr Mirosh, first published at the original source. Preserved copies are kept so the citation survives its host.