|
|
|
|
|
by mountaineer22
3518 days ago
|
|
Could you elaborate on your attack scenarios? Maybe I am wrong, but can you not have multiple LDAP server in a hierarchical relationship? So, for a hackathon, a child LDAP server would be used, but if compromised, would be limited to the administrative capacities of the role created for the hackathon LDAP admin/authentication roles? |
|
- Someone naively sets up error reporting that takes the POST data and logs it somewhere. Employees can now see the passwords from POST data and impersonate each other, or in an even worse case, a vulnerability with the error reporting software can leak the passwords to the public.
- Employees will just leak their own passwords like any human would. LDAP locks you into using one password for everything, making this a much larger risk.