I seem to find open LDAP servers on the Internet more often than I should. Here are some notes on using ldapsearch
Installing ldapsearch on Ubuntu
1
|
Root-DSE object
nmap includes a script to gather info from a LDAP root-dse object (http://nmap.org/nsedoc/scripts/ldap-rootdse.html). We can also use ldapsearch to test:
1
|
Open LDAP server
Connect to an open LDAP server, john the ripper can be used to crack passwords that are returned:
1
|