LDAP injection
Home > Software Quality Glossary > Definition - LDAP injection
EMAIL THIS
Glossary - powered by WhatIs.com
 BROWSE ALPHABETICALLY:    A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #    
Search for: in Full Target Search with Google

LDAP injection

LDAP injection is a specific form of attack that can be employed to compromise Web sites that construct LDAP (Lightweight Directory Access Protocol) statements from data provided by users. This is done by changing LDAP statements so dynamic Web applications can run with invalid permissions, allowing the attacker to alter, add or delete content. LDAP is a protocol that facilitates the location of organizations, individuals and other resources in a network. It is a streamlined version of DAP (Directory Access Protocol), which is part of X.500, a standard for network directory services.

LDAP injection works in much the same manner as SQL injection, a type of security exploit in which the attacker adds SQL (Structured Query Language) code to a Web form input box to gain access to resources or make changes to data. According to security experts, the main reason that LDAP injection and similar exploits are on the rise is the fact that security is not sufficiently emphasized in application development. To protect the integrity of Web sites and applications, experts recommend the implementation of simple precautions during development, such as controlling the types and numbers of characters that are accepted by input boxes.

Read more about it:
>>  The Web Application Security Consortium provides an example of LDAP injection.
>>  SPI Dynamics discusses the technical details of LDAP injection.

Last updated on: Jun 16, 2006

WHITE PAPERS  
WebSphere Application Server Feature Pack for Web 2.0
IBM

PCI Compliance Cut Costs, Not Corners with Third Brigade®
Third Brigade

Improving End-User Performance by Eliminating HTTP Chattiness
F5 Networks

Evolving Work Habits: Changing Your Approach to Network Security
SonicWALL

Identifying and Caching Dynamic Web Applications: A Flexible Approach to Solving Performance Issues
F5 Networks

>> More White Papers
  WHAT'S NEW
 1. Scrum and requirements gathering
 2. Managing performance in the enterprise
 3. Software testing fundamentals
 4. Debugging and unit testing


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts