Lightweight Directory Access Protocol (LDAP) is a protocol used to access and manage directory information.

It is commonly used for providing a central location for accessing and managing directory services. It can be used for

  • Authentication allowing users to have single login credentials across multiple applications and systems.
  • Authorization by managing permissions and access control for network resources.
  • Directory services
  • Synchronization to keep data consistent across multiple systems.

LDAP and Active Directory are related but serve different purposes that specifies the method of accessing and modifying directory services. Whereas AD is a directory service that stores and manages user and computer data. LDAP can communicate with AD and other directory services, it is not a directory itself.

LDAP works by using a client-server architecture

  • A client sends an LDAP request to a server which searches the directory service and returns a response to the client. A request contains
    • Session connection: client connects to the server via an LDAP port
    • Request Type: operation it wants to perform (bind, unbind, search, etc.)
    • Parameters such as a distinguished name (DN) of the entry to be accessed or modified, the scope of the filter.
    • Request ID is the unique identifier to match with the corresponding response from the server.

To interact with LDAP we can use

ldapsearch -H ldap://ldap.example.com:389 -D "cn=admin,dc=example,dc=com" -w secret123 -b "ou=people,dc=example,dc=com" "(mail=john.doe@example.com)"
  • Connect to the server ldap.example.com on port 389.
  • Bind (authenticate) as cn=admin,dc=example,dc=com with password secret123.
  • Search under the base DN ou=people,dc=example,dc=com.
  • Use the filter (mail=john.doe@example.com) to find entries that have this email address.

LDAP Injection

If a web application uses LDAP for authentication or storing user information. To test for LDAP injection we can try the following characters

InputDescription
*An asterisk * can match any number of characters.
( )Parentheses ( ) can group expressions.
|A vertical bar | can perform logical OR.
&An ampersand & can perform logical AND.
(cn=*)Input values that try to bypass authentication or authorisation checks by injecting conditions that always evaluate to true can be used. For example, (cn=*) or (objectClass=*) can be used as input values for a username or password fields.

If an application uses the following LDAP query to authenticate users

(&(objectClass=user)(sAMAccountName=$username)(userPassword=$password))

We can inject the * character into the password field to modify the LDAP query and bypass authentication.