webPromedium

Lab 330 — AuthVault — Blind LDAP Injection in Directory Lookup

hackadvisor

Task: Identity management platform with public LDAP directory lookup, flag hidden in admin's description attribute not returned by API. Solution: Blind boolean-based LDAP injection in username parameter to extract description attribute character by character using wildcard matching.

$ ls tags/ techniques/
ldap_filter_injectiondecoy_flag_identificationblind_ldap_injectionboolean_based_extractionldap_wildcard_matchingparallel_character_bruteforce

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups