Question: The Lightweight Directory Access Protocol ( LDAP ) is used major operating systems to manage objects , including users. Because it often controls what users
The Lightweight Directory Access Protocol LDAP is used major operating systems to manage objects including users. Because it often controls what users can and can not access, it is a popular target for injection attacks. To get a sense of what kind of data is in LDAP, and what you could do if you were able to abuse it let's look at the school's public LDAP database.
Using Isengard, first authenticate to the ADIT aka Windows backend with:
$ kinit
Once you have authenticated, you can use the following command to to search the domain aditmines.edu for Organizational Unit Users:CSM Usersan organizational unit is kind of like a group for the user with the Common Name promig
$ ldapsearch R adit.mines.edu LLL h thunderbolt.adit.mines.edu b OUUsers,OUCSM Users,DCadit,DCmines,DCedu" CNpromig
Look through the results you can see a great deal of information! For example, what year was my account created provide the digit year. ie or year
Think about how might a malicious individual use this information?
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
