{"id":2967,"date":"2024-02-08T12:33:04","date_gmt":"2024-02-08T12:33:04","guid":{"rendered":"https:\/\/www.imperva.com\/learn\/?post_type=application_security&#038;p=2967"},"modified":"2024-02-08T12:33:04","modified_gmt":"2024-02-08T12:33:04","slug":"ldap-injection","status":"publish","type":"application_security","link":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/","title":{"rendered":"LDAP Injection"},"content":{"rendered":"<h2>What is LDAP Injection?<\/h2>\n<p>LDAP injections allow threat actors to compromise the authentication process of certain websites. This vulnerability occurs in websites that use data provided by end users to construct lightweight directory access protocol (LDAP) statements.<\/p>\n<p>LDAP directories are used to store access credentials in the form of objects. The information may be used by a wide range of entities, including users, roles, printers, and servers. When LDAP directories are used for website authentication purposes, threat actors can inject malicious code into user input fields. The actor can then gain unauthorized access to the LDAP directory, where the actor can view or modify usernames and passwords.<\/p>\n<h2>Impact of LDAP injection attacks<\/h2>\n<p>Successful LDAP injections can cause major security breaches, resulting in <a href=\"https:\/\/www.imperva.com\/learn\/data-security\/data-loss-prevention-dlp\/\">data loss<\/a>, damage to the reputation of the organization, and financial losses. Attackers can leverage LDAP injection to steal data, perform session or browser hijacking, and deface of websites.<\/p>\n<p>Additionally, attackers may use LDAP injection attacks to insert malicious software (<a href=\"https:\/\/www.imperva.com\/learn\/application-security\/malware-detection-and-removal\/\">malware<\/a>), which enables them to view user credentials. Attackers may also use this malware to add their own user account to a group of administrators.<\/p>\n<h2>How Does an LDAP Injection Attack Work?<\/h2>\n<p>Applications that use LDAP interact with the LDAP server both on the front end and the back end. LDAP search filters are the LDAP queries which are submitted to the server from the front-end of the application. Filters are built using of prefix notation\u2014for example, here is an LDAP search filter:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2970 lazyload\" alt=\"ldap injection 1\" width=\"567\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png 567w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1-300x48.png 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/p>\n<p>The notation of the prefix filter tells the query to locate an LDAP node with the given password and username. Let&#8217;s take a situation where this query is created by appending the password and username strings taken from an HTML form.<\/p>\n<p>If these values are controlled by the user, are appended to the search filter of the LDAP, without any sanitization or validation. For example, a password and username value of \u201c*\u201d will change the intended interpretation of the query and will return a record of all users.<\/p>\n<p>Other characters may also be used to construct malicious queries. For example, in the query below, the highlighted condition will evaluate as true every time. If this query is employed in an authentication flow, a hacker can bypass authentication measures, because the second part of the statement, requiring a password, will not be evaluated.<\/p>\n<p><img class=\"aligncenter size-full wp-image-2971 lazyload\" alt=\"ldap injection 2\" width=\"592\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-2.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-2.png 592w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-2-300x46.png 300w\" sizes=\"(max-width: 592px) 100vw, 592px\" \/><\/p>\n<h2>Examples of LDAP Injection Attacks<\/h2>\n<p>Here are common examples showing how attackers can perform LDAP injection against vulnerable systems.<\/p>\n<h3>Access Control Bypass<\/h3>\n<p>Consider an LDAP search filter that accepts two fields via a web form\u2014USER and PASSWORD:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2972 lazyload\" alt=\"ldap injection 3\" width=\"364\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-3.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-3.png 364w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-3-300x74.png 300w\" sizes=\"(max-width: 364px) 100vw, 364px\" \/><\/p>\n<p>If the LDAP filter accepts the USER parameter as is, with no sanitization of control characters, an attacker can input a username followed by control characters that break authentication. For example, if the attacker provides this as the USER value:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2973 lazyload\" alt=\"ldap injection 4\" width=\"229\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-4.png\" \/><\/p>\n<p>The LDAP query is constructed as follows:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2974 lazyload\" alt=\"ldap injection 5\" width=\"423\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-5.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-5.png 423w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-5-300x64.png 300w\" sizes=\"(max-width: 423px) 100vw, 423px\" \/><\/p>\n<p>This causes the LDAP server to only process the first part of the query, indicated in bold. The password is not evaluted at all, meaning the attacker can provide any string for password, and gain access.<\/p>\n<h3>Elevation of Privileges<\/h3>\n<p>Consider an LDAP search filter that enforces privileges at the end of a query. For example, a query like the following can be used to display all files in a directory, which are allowed for \u201cguest\u201d level permission:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2975 lazyload\" alt=\"ldap injection 6\" width=\"432\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-6.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-6.png 432w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-6-300x63.png 300w\" sizes=\"(max-width: 432px) 100vw, 432px\" \/><\/p>\n<p>The user provides the value files for the directory parameter, and the system inputs guest as the value for the permission parameter. Similar to the previous example, the attacker can craft a value for the directory parameter that will render the second parameter ineffective.<\/p>\n<p>Suppose the attacker provides this value for the directory parameter:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2976 lazyload\" alt=\"ldap injection 7\" width=\"440\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-7.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-7.png 440w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-7-300x61.png 300w\" sizes=\"(max-width: 440px) 100vw, 440px\" \/><\/p>\n<p>This will construct the following LDAP filter:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2977 lazyload\" alt=\"ldap injection 8\" width=\"752\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-8.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-8.png 752w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-8-300x36.png 300w\" sizes=\"(max-width: 752px) 100vw, 752px\" \/><\/p>\n<p>The LDAP server processes only the first part of the filter, indicated in bold. It sets the permission level to \u201c*\u201d, meaning that all files in the directory will be displayed, elevating the attacker\u2019s privileges. The last part of the query, limiting permission to guest, is ignored.<\/p>\n<h3>Information Disclosure<\/h3>\n<p>Consider an LDAP filter that lists specific resources available in the system (for example, workstations or printers on a network). The query looks like this:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2978 lazyload\" alt=\"ldap injection 9\" width=\"415\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-9.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-9.png 415w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-9-300x65.png 300w\" sizes=\"(max-width: 415px) 100vw, 415px\" \/><\/p>\n<p>If the attacker adds the string uid = * to their query, they can trick the server into listing all the available resources. The attacker provides this value for the Resource1 parameter:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2979 lazyload\" alt=\"ldap injection 10\" width=\"229\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-10.png\" \/><\/p>\n<p>And any value for Resource2. This results in the following query:<\/p>\n<p><img class=\"aligncenter size-full wp-image-2980 lazyload\" alt=\"ldap injection 11\" width=\"491\" height=\"90\" data-src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-11.png\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-11.png 491w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-11-300x55.png 300w\" sizes=\"(max-width: 491px) 100vw, 491px\" \/><\/p>\n<p>The LDAP server applies the OR operator to the two statements indicated in bold, and returns a list of all workstations on the network.<\/p>\n<h2>Preventing LDAP Injection Attacks<\/h2>\n<p>LDAP injection vulnerabilities take place when there is insufficient input cleanup and validation, and queries are created from input that is untrustworthy.<\/p>\n<p>Here are a few ways you can protect your organization from LDAP Injection vulnerabilities:<\/p>\n<ul>\n<li aria-level=\"1\">Ensure adequate encoding\u2014as is the case with different injection attacks, it is critical that there is adequate encoding at the application layer and rigorous login validation, to stop LDAP injection vulnerabilities.<\/li>\n<li aria-level=\"1\">Sanitize inputs\u2014each user input employed within LDAP queries has to be sanitized in keeping with application stipulations, and every LDAP special characters, including ( ) ! | &amp; * have to be safely encoded.<\/li>\n<li aria-level=\"1\">Avoid special characters\u2014for maximum security, do not use special characters at all in your queries, and avoid combining LDAP filters.<\/li>\n<li aria-level=\"1\">Use a whitelist\u2014before you include an untrustworthy entry in LDAP queries, the entry should be validated in contrast to a whitelist of permitted characters or strings (for example, a user name should be examined against a list of known users). This verification must alway be carried out on the server side, even if the input has previously been authenticated on the client side.<\/li>\n<li aria-level=\"1\">Escape all user input if possible\u2014to avoid input strings controlled by the user, which may include control characters, escape all characters provided by a user. For instance, with a Java application, you can use backslashes as escape characters. This means that untrusted user entries are included in the search filter as literal string values, rather than logical LDAP statements.<\/li>\n<li aria-level=\"1\">Use directory authorization\u2014this technique strives to limit the impact of any attempts at injection by minimizing privileges. The LDAP account used for mounting an application directory should have the minimal privileges required from the application. This means that even if the application is compromised via injection, it will not grant the attacker unlimited access to the underlying host machine.<\/li>\n<li aria-level=\"1\">Write test scripts\u2014when creating software that includes LDAP queries, your team must ensure that LDAP injection does not affect them. Write LDAP injection test scripts as part of any application code that integrates with LDAP, and do not release a new version of the application until those tests pass.<\/li>\n<\/ul>\n<h2>LDAP Injection with Imperva<\/h2>\n<p>Imperva provides the industry-leading <a href=\"https:\/\/www.imperva.com\/products\/web-application-firewall-waf\/\">Web Application Firewall<\/a>, which can prevent LDAP injection and many other attacks against your web applications.<\/p>\n<p>Beyond LDAP injection protection, Imperva provides comprehensive protection for applications, APIs, and microservices:<\/p>\n<p><a href=\"https:\/\/www.imperva.com\/products\/runtime-application-self-protection-rasp\/\">Runtime Application Self-Protection (RASP)<\/a> &#8211; Real-time attack detection and prevention from your application runtime environment goes wherever your applications go. Stop external attacks and injections and reduce your vulnerability backlog.<\/p>\n<p><a href=\"https:\/\/www.imperva.com\/products\/api-security\/\">API Security<\/a> &#8211; Automated API protection ensures your API endpoints are protected as they are published, shielding your applications from exploitation.<\/p>\n<p><a href=\"https:\/\/www.imperva.com\/products\/advanced-bot-protection-management\/\">Advanced Bot Protection<\/a> &#8211; Prevent business logic attacks from all access points &#8211; websites, mobile apps and APIs. Gain seamless visibility and control over bot traffic to stop online fraud through account takeover or competitive price scraping.<\/p>\n<p><a href=\"https:\/\/www.imperva.com\/products\/ddos-protection-solutions\/\">DDoS Protection<\/a> &#8211; Block attack traffic at the edge to ensure business continuity with guaranteed uptime and no performance impact. Secure your on premises or cloud-based assets \u2013 whether you\u2019re hosted in AWS, Microsoft Azure, or Google Public Cloud.<\/p>\n<p><a href=\"https:\/\/www.imperva.com\/products\/attack-analytics\/\">Attack Analytics<\/a> &#8211; Ensures complete visibility with machine learning and domain expertise across the application security stack to reveal patterns in the noise and detect application attacks, enabling you to isolate and prevent attack campaigns.<\/p>\n<p><a href=\"https:\/\/www.imperva.com\/products\/client-side-protection\/\">Client-Side Protection<\/a> &#8211; Gain visibility and control over third-party JavaScript code to reduce the risk of supply chain fraud, prevent data breaches, and client-side attacks.<\/p>\n","protected":false},"featured_media":0,"template":"","categories":[3],"class_list":["post-2967","application_security","type-application_security","status-publish","hentry","category-attack-types"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What is LDAP Injection | Examples &amp; Prevention | Imperva<\/title>\n<meta name=\"description\" content=\"Protect your site from LDAP Injection attacks: Learn how they compromise authentication, their impacts, and effective prevention strategies.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is LDAP Injection | Examples &amp; Prevention | Imperva\" \/>\n<meta property=\"og:description\" content=\"Protect your site from LDAP Injection attacks: Learn how they compromise authentication, their impacts, and effective prevention strategies.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/\" \/>\n<meta property=\"og:site_name\" content=\"Learning Center\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"8 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Naor Kahana\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/\",\"url\":\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/\",\"name\":\"What is LDAP Injection | Examples & Prevention | Imperva\",\"isPartOf\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png\",\"datePublished\":\"2024-02-08T12:33:04+00:00\",\"description\":\"Protect your site from LDAP Injection attacks: Learn how they compromise authentication, their impacts, and effective prevention strategies.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#primaryimage\",\"url\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png\",\"contentUrl\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png\",\"width\":567,\"height\":90,\"caption\":\"ldap injection 1\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.imperva.com\/learn\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AppSec\",\"item\":\"https:\/\/www.imperva.com\/learn\/application-security\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"LDAP Injection\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.imperva.com\/learn\/#website\",\"url\":\"https:\/\/www.imperva.com\/learn\/\",\"name\":\"Learning Center\",\"description\":\"Imperva\",\"publisher\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.imperva.com\/learn\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.imperva.com\/learn\/#organization\",\"name\":\"Imperva Inc\",\"url\":\"https:\/\/www.imperva.com\/learn\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.imperva.com\/learn\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2023\/06\/Linkedin-FB-OG-sharing.jpeg\",\"contentUrl\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2023\/06\/Linkedin-FB-OG-sharing.jpeg\",\"width\":1200,\"height\":627,\"caption\":\"Imperva Inc\"},\"image\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is LDAP Injection | Examples & Prevention | Imperva","description":"Protect your site from LDAP Injection attacks: Learn how they compromise authentication, their impacts, and effective prevention strategies.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/","og_locale":"en_US","og_type":"article","og_title":"What is LDAP Injection | Examples & Prevention | Imperva","og_description":"Protect your site from LDAP Injection attacks: Learn how they compromise authentication, their impacts, and effective prevention strategies.","og_url":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/","og_site_name":"Learning Center","og_image":[{"url":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"8 minutes","Written by":"Naor Kahana"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/","url":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/","name":"What is LDAP Injection | Examples & Prevention | Imperva","isPartOf":{"@id":"https:\/\/www.imperva.com\/learn\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#primaryimage"},"image":{"@id":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#primaryimage"},"thumbnailUrl":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png","datePublished":"2024-02-08T12:33:04+00:00","description":"Protect your site from LDAP Injection attacks: Learn how they compromise authentication, their impacts, and effective prevention strategies.","breadcrumb":{"@id":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#primaryimage","url":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png","contentUrl":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2024\/02\/ldap-injection-1.png","width":567,"height":90,"caption":"ldap injection 1"},{"@type":"BreadcrumbList","@id":"https:\/\/www.imperva.com\/learn\/application-security\/ldap-injection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.imperva.com\/learn\/"},{"@type":"ListItem","position":2,"name":"AppSec","item":"https:\/\/www.imperva.com\/learn\/application-security\/"},{"@type":"ListItem","position":3,"name":"LDAP Injection"}]},{"@type":"WebSite","@id":"https:\/\/www.imperva.com\/learn\/#website","url":"https:\/\/www.imperva.com\/learn\/","name":"Learning Center","description":"Imperva","publisher":{"@id":"https:\/\/www.imperva.com\/learn\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.imperva.com\/learn\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.imperva.com\/learn\/#organization","name":"Imperva Inc","url":"https:\/\/www.imperva.com\/learn\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.imperva.com\/learn\/#\/schema\/logo\/image\/","url":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2023\/06\/Linkedin-FB-OG-sharing.jpeg","contentUrl":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2023\/06\/Linkedin-FB-OG-sharing.jpeg","width":1200,"height":627,"caption":"Imperva Inc"},"image":{"@id":"https:\/\/www.imperva.com\/learn\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/application_security\/2967","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/application_security"}],"about":[{"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/types\/application_security"}],"version-history":[{"count":3,"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/application_security\/2967\/revisions"}],"predecessor-version":[{"id":2982,"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/application_security\/2967\/revisions\/2982"}],"wp:attachment":[{"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/media?parent=2967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/categories?post=2967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}