Web Hack List

Other nomination

SSRF Protocol Smuggling in Plaintext Credential Handlers : LDAP

LDAP client libraries pass CRLF through in the username and password of a plaintext simple bind, so an application letting a user set the LDAP server, port and credentials becomes an SSRF that can speak other plaintext TCP protocols. The example smuggles a whole Redis command sequence in the password field to write a PHP web shell into the web root.

Record

Researcher
Willis Vandevanter

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Willis Vandevanter, first published at the original source. Preserved copies are kept so the citation survives its host.