3 ms·
My biggest peeve with LDAP is the fact that it does anonymous login by default if no password is supplied. This combined with the fact that many libaries for L
by EJTH 10y ago
My biggest peeve with LDAP is the fact that it does anonymous login by default if no password is supplied.
This combined with the fact that many libaries for LDAP is basicly wrappers for C libaries you have the perfect vector for attack in many places such as PHP and node.js where a null byte in a string doesn't mark the end of a string, because it will usually be trivial to inject a nullbyte character and most devs just check for string length...
I have found nullbyte injection flaws in both our node and PHP apps that talk directly to our LDAP server, even code from very competent devs, because no one seems to think that node.js would have the same flaw as PHP in regards to null byte injection in library calls.