Web Hack List

Collected research

A Journey from JNDI/LDAP Manipulation to Remote Code Execution Dream Land

When a Java application performs a JNDI lookup on an attacker-controlled name, the attacker serves a naming reference over RMI, CORBA or LDAP that makes the victim fetch and instantiate a remote factory class, giving code execution. A poisoned LDAP directory entry achieves the same against applications that merely search it.

Record

Researcher
Alvaro Muñoz and Oleksandr Mirosh
Published by
blackhat.com
Format
Whitepaper
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alvaro Muñoz and Oleksandr Mirosh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .