Hunt Ldap

Hunt LDAP Injection and XPath Injection — authentication bypass, blind char-by-char attribute exfiltration, AD user/group enumeration, XML-store XPath bypass. Covers the LDAP special-character set (* ( ) \ NUL /), search-filter-context vs DN-injection, parenthesis-balancing, AND/OR filter logic, and {SSHA}/{CRYPT} userPassword exfil on non-AD directories. Use when target uses LDAP/AD authentication, corporate SSO with a directory backend, an address-book/people-search API, or XML-based data stores queried with XPath.

uphiago c47691a 16.6 KB Updated

File contents

uphiago/recon-skills/tree/main/redteam/hunt-ldap commit c47691a80d

Frequently asked questions

npx skillmds@latest add uphiago/hunt-ldap