LDAP Injection

Description

Lightweight Directory Access Protocol (LDAP) is used by web applications to access and maintain directory information services. One of the most common uses for LDAP is to provide a Single - Sign - On(SSO) service that will allow clients to authenticate with a web site without any interaction(assuming their credentials have been validated by the SSO provider). LDAP injection occurs when untrusted data is used by the web application to query the LDAP directory without prior sanitisation.

Products, Sensors, and Dependencies

ProductDependenciesData sourceAccess requiredProtocolData CollectedNotes

References

LDAP Injection

Attack Path Technique Details

Framework: OWASP

Family: Injection

Technique: LDAP Injection

Products Required: Tenable Web App Scanning