Web Hack List

Collected research

SSRF Protocol Smuggling in Plaintext Credential Handlers : LDAP

LDAP client libraries pass CRLF through in the username and password of a plaintext simple bind, so an application letting a user set the LDAP server, port and credentials becomes an SSRF that can speak other plaintext TCP protocols. The example smuggles a whole Redis command sequence in the password field to write a PHP web shell into the web root.

Record

Researcher
Willis Vandevanter
Published by
silentrobots.com
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Willis Vandevanter, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .