Skip to content

Prevent error for ldap login with invalid characters#14160

Merged
rodrigok merged 3 commits intodevelopfrom
ldap-login-error
Apr 17, 2019
Merged

Prevent error for ldap login with invalid characters#14160
rodrigok merged 3 commits intodevelopfrom
ldap-login-error

Conversation

@rodrigok
Copy link
Member

No description provided.

@erhan-
Copy link
Contributor

erhan- commented Apr 17, 2019

@rodrigok Have you been able to exploit this LDAP injection? I have been trying for a while but I am not sure if the LDAP injection methods work for the LDAP bind.
Things like * as username will return the first user in the LDAP tree but this won't authenticate you in any way imho. Have you guys found a way?

Obviously I am not good with LDAP and receive different errors like:
ProtocolError: Bad search filter

@rodrigok rodrigok changed the title Prevent error for ldap login with invalid characters [WIP] Prevent error for ldap login with invalid characters Apr 17, 2019
@rodrigok
Copy link
Member Author

@erhan- I wasn't, this just prevent some utf8 errors.

@rodrigok rodrigok requested a deployment to rocket-chat-pr-14160 April 17, 2019 20:15 Abandoned
@rodrigok rodrigok changed the title [WIP] Prevent error for ldap login with invalid characters Prevent error for ldap login with invalid characters Apr 17, 2019
@rodrigok rodrigok merged commit aeb1d1c into develop Apr 17, 2019
@rodrigok rodrigok deleted the ldap-login-error branch April 17, 2019 20:34
@rodrigok rodrigok mentioned this pull request Apr 28, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

Comments