hunt-ldap - Hunt LDAP and XPath Injection
Tests LDAP and XPath injection paths for authentication bypass, blind attribute extraction, directory enumeration, and non-AD password-hash exposure.
Tags
Updated: 2026-10-02Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Probe LDAP input handling
- Test authentication bypass
- Enumerate directory attributes
- Extract attributes blindly
- Assess XPath authentication bypass
- Distinguish AD from generic LDAP
Inputs
- Target URL and API paths
- LDAP or AD authentication context
- XML-backed authentication context
- Test usernames and passwords
- Baseline HTTP responses
Outputs
- Authentication bypass indicators
- Directory enumeration results
- Blindly recovered attribute values
- Non-AD userPassword hashes
- LDAP or XPath error responses
- HTTP status and size comparisons
Requirements
- Authorized testing permission
- Network access to target
- Bash shell
- curl
- Python 3
