Collected research
SSRF Protocol Smuggling in Plaintext Credential Handlers : LDAP
LDAP client libraries pass CRLF through in the username and password of a plaintext simple bind, so an application letting a user set the LDAP server, port and credentials becomes an SSRF that can speak other plaintext TCP protocols. The example smuggles a whole Redis command sequence in the password field to write a PHP web shell into the web root.
Record
- Researcher
- Willis Vandevanter
- Published by
- silentrobots.com
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Willis Vandevanter, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .