Web Application Pentesting > Injection Attacks > LDAP Injection

Task 1
Introduction
- Deploy the target VM attached to this task by pressing the green Start Machine button. We will use the machine’s generated IP address later at the end of the room. You can access the VM using your VPN connection or the AttackBox.
No answer needed
Structure
- Click me to proceed to the next task.
No answer needed
Search Queries
- Click me to proceed to the next task.
No answer needed
Injection Fundamentals
- Click me to proceed to the next task.
No answer needed
Exploting LDAP
- What is the flag?
THM{!b451c_ld4p_inj3ct1ON!}
Blind LDAP Injection
- Click me to proceed to the next task.
No answer needed
Automating the Exploitation
- What is the flag in the dashboard?
THM{!!bl1nDLd4P1nj3ct10n!!}
Conclusion
- I can now exploit LDAP Injection vulnerabilities!
No answer needed