01.09.2015 Views

4.0

1NSchAb

1NSchAb

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

132<br />

Web Application Penetration Testing<br />

will be represented as:<br />

find(“(&(cn=John)(userPassword=mypass))”)<br />

Boolean conditions and group aggregations on an LDAP search filter<br />

could be applied by using the following metacharacters:<br />

Metachar<br />

Meaning<br />

the filter will look like:<br />

searchfilter=”(cn=*)”<br />

which matches every object with a ‘cn’ attribute equals to anything.<br />

If the application is vulnerable to LDAP injection, it will display<br />

some or all of the users’ attributes, depending on the application’s<br />

execution flow and the permissions of the LDAP connected user.<br />

&<br />

|<br />

!<br />

=<br />

~=<br />

>=<br />

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!