Re: LDAP + Active Directory

From: Patrick Patterson (ppattersonat_private)
Date: Sat Oct 13 2001 - 11:17:38 PDT

  • Next message: Sacha Faust: "RE: LDAP + Active Directory"

    -----BEGIN PGP SIGNED MESSAGE-----
    
    On Saturday 13 October 2001 00:13, Tim Russo wrote:
    > I have discovered that I am able to connect anonymously to my clients
    > active directory/LDAP port (389). Using an LDAP client I can connect, but I
    > do not see any information. Is this because the directory is empty or that
    > I am not using the correct protocol version (3?) and/or BaseDN? Is their a
    > way to get a listing not knowing the correct DC?
    >
    
    We were actually playing with this last night in our lab, and here is what we
    found:
    
    Using an LDAP Browser that we found called GQ (Requires GNOME and Linux)
    (http://biot.com/gq/) - we were able to get a listing of the top level of the
    Active Directory Tree: (no need to feed a base DN)
    
    cn=Schema,cn=Configuration,dc=example,dc=com
    cn=Configuration,dc=example,dc=com
    dc=example,dc=com
    
    This appears to be the extent of the anonymous browse capabilities (we only
    played with it for a few hours, so YMMV)
    
    If you are able to connect as the Administrator:
    
    cn=Administrator,cn=Users,dc=example,dc=com
    
    then you can enumerate the users, and all sorts of other fun things ;)
    
    Users are under cn=Users,dc=example,dc=com
    Computers are under cn=Computers,dc=example,dc=com
    
    Anyways, hope this helps ;)
    
    
    - --
    
    Patrick Patterson			Tel: (514) 485-0789
    Chief Security Architect		Fax: (514) 485-4737
    Carillon Information Security Inc.	E-Mail: ppattersonat_private
    - -----------------------------------------------------------------------
    		The New Sound of Network Security
    		     http://www.carillonIS.com
    
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGPfreeware 5.0i for non-commercial use
    MessageID: u9lk+xQIFEUSLRN0QznTUvV9wP8nOu2X
    
    iQCVAwUBO8iFRrqc3sMKNyclAQFE/AQAn7Kpaiu8lGgSUkBA7eG4bZnoDLamwLUK
    +YgKyLGddyBcEJcu40V8qyzQr/8cDzO13nWA2HRpWE34sfXDs3yHOCqH1UwAX+4R
    l8Y8vx9S6lB+qfjmqQ+tX8hzMGi7guOPrYRUNnJKUF/4ZR2uMOv7hOcsL1SoLzwB
    MO0nJy1UXwQ=
    =tUMW
    -----END PGP SIGNATURE-----
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Sat Oct 13 2001 - 19:06:10 PDT