webhard

Авторизация 2.0 (Authorization 2.0)

hackerlab

Task: LDAP authentication web app with WAF blocking classic injection patterns. Solution: Bypass WAF by inserting character between *)( pattern, inject LDAP filter via password field to authenticate as administrator.

$ ls tags/ techniques/
ldap_filter_injectionwaf_pattern_analysiswaf_bypass_char_insertionldap_wildcard_matchsession_role_escalation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]