• search hit 2 of 6
Back to Result List

LanDscAPe: Exploring LDAP Weaknesses and Data Leaks at Internet Scale

  • The Lightweight Directory Access Protocol (LDAP) is the standard technology to query information stored in directories. These directories can contain sensitive personal data such as usernames, email addresses, and passwords. LDAP is also used as a central, organization-wide storage of configuration data for other services. Hence, it is important to the security posture of many organizations, not least because it is also at the core of Microsoft’s Active Directory, and other identity management and authentication services. We report on a large-scale security analysis of deployed LDAP servers on the Internet. We developed LanDscAPe, a scanning tool that analyzes security-relevant misconfigurations of LDAP servers and the security of their TLS configurations. Our Internet-wide analysis revealed more than 10k servers that appear susceptible to a range of threats, including insecure configurations, deprecated software with known vulnerabilities, and insecure TLS setups. 4.9k LDAP servers host personal data, and 1.8k even leak passwords. We document, classify, and discuss these and briefly describe our notification campaign to address these concerning issues.
Bitte benutzen Sie diese Referenz, um auf diese Ressource zu verweisen:
https://doi.org/10.25974/fhms-18157

Download full text files

Export metadata

Additional Services

Metadaten
Author:Jonas Kaspereit, Gurur Öndarö, Gustavo Luvizotto Cesar, Simon Ebbers, Fabian Ising, Christoph Saatjohann, Mattijs Jonker, Ralph Holz, Sebastian Schinzel
URN:urn:nbn:de:hbz:836-opus-181577
URL:https://www.usenix.org/system/files/usenixsecurity24-kaspereit.pdf
DOI:https://doi.org/10.25974/fhms-18157
ISBN:978-1-939133-44-1
Parent Title (English):33rd USENIX Security Symposium (USENIX Security 24)
Document Type:Conference Proceeding
Language:English
Date of Publication (online):2024/09/05
Year of first Publication:2024
Provider of the Publication Server:FH Münster - University of Applied Sciences
Release Date:2024/09/05
Faculties:Elektrotechnik und Informatik (ETI)
Publication list:Schinzel, Sebastian
Saatjohann, Christoph
Ising, Fabian
Licence (German):License LogoZweitveroeffentlichung