[+] Vurnerebility: LDAP Injection [+] Category : Implemented Web exploit [+] Category : Attack Technique [+] Author : mc2_s3lector [+] dork : X/o\" [+] Contact : www.yogyacarderlink.web.id [+] date : 4-2-10 [+] biGthank to : Allah SWT,jasakom,KeDai Computerworks,0n3-d4y n3ro,eplaciano, all*.indonesian like a coding, --------------------------------------------------------------------------------------------------------------------------------------------------- Directory acces protokol/directory manipulation,protokol breaker->standar protocol,query custom statement,page request,componen execute command,data base server,web apps services modify,remove etc. --------------------------------------------------------------------------------------------------------------------------------------------------- code:
<%@ Language=VBScript %> <% Dim userName Dim filter Dim ldapObj Const LDAP_SERVER = "ldap.example" userName = Request.QueryString("user")<-----------*1(LOOK THIS BUG LINE PARAMETER USER=EMPTY) ( userName = "" ) then Response.Write("Invalid request. Please specify a valid user name")
Write("User
information for : " +
ldapObj.AttrValue(0) + "
")
For i = 0 To ldapObj.AttrCount -1
Response.Write("" +
ldapObj.AttrType(i) +
" : " + ldapObj.AttrValue(i) + "
" )
Response.Write("