From: Francis Cianfrocca Date: 2007-08-25T00:24:59+09:00 Subject: Re: ldap injection ------=_Part_64891_14141734.1187969095628 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline On 8/24/07, Jeff - Burly Systems wrote: > > By ldap injection ( > http://www.webappsec.org/projects/threat/classes/ldap_injection.shtml > ), I was talking about potential security vulnerabilities, similar to > sql injection ( http://manuals.rubyonrails.com/read/chapter/43 ) > attacks, and was wondering if Net::LDAP implemented anything internal > (similar to the use of ? in sql query strings in ruby-dbi or > ActiveRecord ) to help prevent such., or if I needed to test for and > attempt to cleanse any such potentially malicious user input > (especailly in regards to uid) before using Net::LDAP. > > I'll check out bind_as tho. Thanks, It's always a good idea to scrub user input anyway. In your example, you're getting a string from the user that might be crafted to carry an attack. In your code, the string will get passed to an LDAP bind, not a search. If the attacker doesn't provide a correct authentication, he won't get anywhere. Assuming proper access controls in your directory, subsequent search requests will only retrieve data that the authenticated user is allowed to see. Also assuming proper access control, the user won't be able to add, change or delete data. Net::LDAP has an API for constructing filters that allows you to build them up branch by branch. If you're concerned about maliciously-crafted search filters, use that API and scrub the incoming data carefully. Bottom line, if your directory is badly designed, you can be vulnerable. Without knowing your specifics, I can't give advice beyond that. ------=_Part_64891_14141734.1187969095628--