LDAP null base returns information |
---|
Risk Level: | Medium | Check or Attack Name: LDAP NullBase |
---|---|---|
Platforms: | LDAP | |
Description: | If LDAP allows a NULL base in an LDAP search, a user can run a search that returns information on namingContexts and supported controls. |
|
Remedy: | Use an access list control to prevent users from dumping the base of the tree or issuing a request without knowing the base object. |
|
References: |
Know Your Risks |