Full Disclosure mailing list archives

LDAP username special char Problem


From: "Jellbauer Jakob" <Jakob.Jellbauer () interhyp de>
Date: Thu, 17 Mar 2005 19:37:45 +0100

Hi,

today i followed this scenario:

a user tried to connect to Windows 2000 ActiveDirectory trough LDAP, and misspelled the loginname like :

usérname or usêrname  (with special char like  `  or ^ or  ´ )

and is succesfully connected ! 

is this a known "feature" or problem ?

i reproduced it with php ldap functions and with Softerra LDAP Browser 

greetings

jakob




Jakob Jellbauer
Junior Network & Systemadministrator
Interhyp AG
Parkstadt Schwabing
Marcel-Breuer-Straße 18
80807 München
fon: +49 (89) 76 77 21 47
fax: +49 (89) 76 77 251 47
mailto:jakob.jellbauer () interhyp de
http://www.interhyp.de


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://www.secunia.com/


Current thread: