Demystifying Java JNDI attacks

How this Java API — rather its implementation could have catastrophic consequences on your application’s security, and what can you do about it?

Ax Sharma

--

Ax Sharma: Sample bytecode representation of a Java application class

JNDI-based attacks have wreaked havoc on mission-critical Java applications in the last few years — not because of anything being wrong with this API itself, rather the…

--

--