What problem does it solve?
This skill addresses the challenge of identifying and exploiting LDAP and XPath injection vulnerabilities in directory authentication systems and XML-backed data stores, which are often under-tested but can lead to critical security breaches including authentication bypass, sensitive data exfiltration, and enterprise Active Directory compromise.
Core Features & Use Cases
- LDAP Injection Exploitation: Includes validated payloads for authentication bypass, blind char-by-char attribute exfiltration, and non-AD userPassword hash extraction.
- XPath Injection Testing: Provides balanced payloads for XML-backed authentication bypass and node data dumping.
- Active Directory Enumeration: Enables wildcard-based discovery of users, groups, and privileged accounts via LDAP filters, including identification of admin accounts with plaintext credentials in description fields.
- Use Case: Ideal for authorized penetration tests and red team engagements targeting corporate SSO portals, employee directory APIs, legacy Java/PHP applications with directory backends, and XML-based authentication systems.
Quick Start
Use the hunt-ldap skill to test your organization's corporate SSO login endpoint for LDAP injection vulnerabilities and attempt a safe, controlled authentication bypass using balanced filter payloads to validate the finding.