webmedium

Directory

volgactf

Task: Corporate directory service with LDAP backend and JWT auth — bypass authentication and find hidden data. Solution: LDAP wildcard injection in email/telephone fields to bypass auth, then brute-force organizational unit parameter to discover hidden OU containing the flag.

$ ls tags/ techniques/
ldap_wildcard_injectionauth_bypass_via_wildcardou_brute_forceldap_base_dn_manipulationhint_analysis

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]