webPromedium

Lab 331 — PeopleDir — LDAP Injection Authentication Bypass

hackadvisor

Task: Corporate HR portal with LDAP authentication, goal is to bypass auth and access admin panel. Solution: LDAP wildcard injection in password field using * to match any password, then access classified records as admin.

$ ls tags/ techniques/
ldap_filter_injectionldap_wildcard_bypassauthentication_bypass_to_admin

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups