LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

hunt-ldap - Hunt LDAP and XPath Injection

Tests LDAP and XPath injection paths for authentication bypass, blind attribute extraction, directory enumeration, and non-AD password-hash exposure.

Tags

Updated: 2026-10-02

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Probe LDAP input handling
  • Test authentication bypass
  • Enumerate directory attributes
  • Extract attributes blindly
  • Assess XPath authentication bypass
  • Distinguish AD from generic LDAP

Inputs

  • Target URL and API paths
  • LDAP or AD authentication context
  • XML-backed authentication context
  • Test usernames and passwords
  • Baseline HTTP responses

Outputs

  • Authentication bypass indicators
  • Directory enumeration results
  • Blindly recovered attribute values
  • Non-AD userPassword hashes
  • LDAP or XPath error responses
  • HTTP status and size comparisons

Requirements

  • Authorized testing permission
  • Network access to target
  • Bash shell
  • curl
  • Python 3

Source

  • Spec: SKILL.md
ldap
xpath-injection
red-team
authentication-bypass
directory-enumeration
Probe LDAP input handling
Test authentication bypass
Enumerate directory attributes
Extract attributes blindly
Target URL and API paths
LDAP or AD authentication context
XML-backed authentication context
Authentication bypass indicators
Directory enumeration results
Blindly recovered attribute values