MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

hunt-ldap

hunt-ldap is an code AI skill with a core value of Hunt LDAP Injection and XPath Injection. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Hunt LDAP Injection and XPath Injection

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/hunt-ldap && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/hunt-ldap/SKILL.md -o ./skills/hunt-ldap/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

> **⚠️ AUTHORIZED USE ONLY**

> This skill is for educational purposes or authorized security assessments only.

> You must have explicit, written permission from the system owner before using this tool.

> Misuse of this tool is illegal and strictly prohibited.


> **Mandatory confirmation gate**

> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

> 1. Ask the user to state the exact target URL, IP, account, or resource.

> 2. Ask the user to confirm written authorization and the permitted scope.

> 3. Show the exact command(s) and explain their expected effect.

> 4. Wait for explicit confirmation in the current conversation.

>

> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.


# HUNT-LDAP — LDAP Injection & XPath Injection


> Grounding note: LDAP injection is rarely disclosed with verbatim payloads on

> public platforms (most live on internal-pentest reports). This skill is

> grounded in the **OWASP LDAP Injection Prevention / Testing Guide

> (WSTG-INPV-06)**, **PortSwigger Web Security Academy (LDAP injection)**, and

> the **RFC 4515** filter grammar — all publicly verifiable references rather

> than invented HackerOne IDs. Do not cite a report you cannot link.


Crown Jewel Targets


LDAP injection that bypasses authentication = **Critical**. Blind attribute

exfiltration of credentials/secrets = **High**. AD enumeration alone = Medium-High.


**Highest-value chains:**

- **LDAP auth bypass** — close the `uid` filter and append an always-true OR so the

bind/search returns the admin entry without a valid password.

- **Blind attribute exfil** — char-by-char extraction of an attribute value via a

boolean oracle (login success/failure, result count, or response length).

- **userPassword hash exfil (non-AD only)** — on OpenLDAP/389-DS the

`userPassword` attribute can hold `{SSHA}`/`{CRYPT}` hashes that ARE readable

by query. See the AD-vs-generic warning below.

- **XPath injection auth bypass** — `' or '1'='1` against XML-backed auth.


---


CRITICAL — Active Directory vs generic LDAP


Do **not** conflate the two. They behave very differently:


| | Generic LDAP (OpenLDAP, 389-DS, ApacheDS) | Active Directory |

|---|---|---|

| Password attribute | `userPassword` — may hold `{SSHA}`/`{MD5}`/`{CRYPT}` and **is readable** if ACL allows | `unicodePwd` — **write-only**, never returned by any search |

| Hash exfil via injection | **Possible** where ACLs leak `userPassword` | **Not possible** — there is no readable hash attribute over LDAP |

| Useful enum attrs | `uid`, `cn`, `mail`, `userPassword` | `sAMAccountName`, `userPrincipalName`, `mail`, `memberOf`, `description` (often holds plaintext secrets!) |


**Do not tell a reader that blind LDAP injection yields AD password hashes — it

does not.** `unicodePwd` is write-only. Against AD, the win is enumeration

(`sAMAccountName`, `memberOf`, `description`/`info` fields that admins misuse to

store passwords) and auth bypass — not hash dumping. The hash-exfil technique

applies **only** to non-AD directories exposing `userPassword`.


---


Attack Surface Signals


text
Corporate SSO / intranet login pages (often legacy Java/Spring/PHP)
Windows + IIS + "integrated" directory auth
/api/ldap/*  /api/directory/*  /people  /address-book  /search?dir=
"Find a colleague" / org-chart / employee-search features
XML-backed config or auth → XPath injection candidate
Error strings that confirm an LDAP backend:
  javax.naming.NameNotFoundException
  javax.naming.directory.InvalidSearchFilterException
  LDAP: error code 49 - 80090308  (AD invalid creds / bind failure)
  com.sun.jndi.ldap.*  /  System.DirectoryServices  /  ldap_search():
  "Bad search filter"  /  net.ldap (Go)  /  python-ldap SERVER_DOWN

---


LDAP filter grammar (RFC 4515) — why injection works


A login filter is typically built by string-concat:


text
(&(ui

🎯 Best For

  • Claude users
  • Software engineers
  • Development teams
  • Tech leads

💡 Use Cases

  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply hunt-ldap to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Is hunt-ldap compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for hunt-ldap?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install hunt-ldap?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/hunt-ldap/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills