LDAP monitor information gathering |
---|
Risk Level: | Medium | Check or Attack Name: LDAP monitor |
---|---|---|
Platforms: | LDAP | |
Description: | A potential attacker can gain information about the LDAP server by accessing the LDAP monitor. The LDAP server dumps monitoring information, such as the LDAP server version, the connections, the number of backends, and who's logged on. |
|
Remedy: | Disable the cn=monitor entry or allow only authorized users to view this entry. |
|
References: |
Know Your Risks |