LDAP config information available |
---|
Risk Level: | Medium | Check or Attack Name: LDAP Config |
---|---|---|
Platforms: | LDAP | |
Description: | A potential attacker can gain information about the LDAP server by accessing the LDAP configuration. The configuration information can show what sort of backend is being used. |
|
Remedy: | Disable the cn=config entry or allow only authorized users to view the entry. |
|
References: |
Know Your Risks |