webPromedium
Lab 331 — PeopleDir — LDAP Injection Authentication Bypass
hackadvisor
Task: Corporate HR portal with LDAP authentication, goal is to bypass auth and access admin panel. Solution: LDAP wildcard injection in password field using * to match any password, then access classified records as admin.
$ ls tags/ techniques/
ldap_filter_injectionldap_wildcard_bypassauthentication_bypass_to_admin
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 330 — AuthVault — Blind LDAP Injection in Directory Lookup— hackadvisor
- [web][Pro]Directory— volgactf
- [web][Pro]Lab 326 — PulseBoard — NoSQL Injection in Authentication— hackadvisor
- [web][Pro]Lab 329 — PipelineIQ — NoSQL Injection Authentication Bypass— hackadvisor
- [web][Pro]Lab 328 — DataNest — NoSQL Operator Injection in Authentication— hackadvisor