LDAP null subtree allows user to gain information |
---|
Risk Level: | Medium | Check or Attack Name: LDAP NullSubtree |
---|---|---|
Platforms: | LDAP | |
Description: | If LDAP allows a NULL base in an LDAP search with a scope set to subtree, the LDAP server will dump all viewable information in a directory. |
|
Remedy: |
|
|
References: |
Know Your Risks |