oss-sec mailing list archives
Re: watch for LDAP anonymous binds and empty passwords
From: yersinia <yersinia.spiros () gmail com>
Date: Thu, 17 Sep 2009 11:28:13 +0200
On Thu, Sep 17, 2009 at 12:54 AM, Steven M. Christey <coley () linus mitre org>wrote:
FYI, we've seen "LDAP anonymous binds and empty passwords" a couple times in CVE, the latest being PostgreSQL (IDs forthcoming). This smells like a general vuln class to me, so developers may want to re-examine their LDAP support. CVE-2009-1905 and CVE-2007-6714 are examples. I haven't investigated closely but the pattern may be that a blank password can return successful authentication when anonymous binds are allowed. There's a relatively rare history of LDAP-specific vulns, which suggests to me that not a lot of people have been looking for this. I yes, because i am a LDAP expert (or so) and have worked with 4 different
Directory Server. Vulnerabilities as this, but only for some proprietary product, are leading some security scanners like nessus, but not only, to signal vulnerability for LDAP bind null, LDAP null base SEARCH and so. For this many LDAP administrators are forced by their security deparment,who are ignorant of these details but follow what they say the tools without understanding the implications, to configure their LDAP server by disabling the anonymous bind in general, also to the LDAP root DSE. But this is in direct violation of RFC LDAP and subsequently causing a large quantity of issues with other products that follow the RFC. Free to ask if you want more details. Best Regards Elia - Steve
Current thread:
- watch for LDAP anonymous binds and empty passwords Steven M. Christey (Sep 16)
- Re: watch for LDAP anonymous binds and empty passwords yersinia (Sep 17)