what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

as400ldap.txt

as400ldap.txt
Posted Mar 29, 2005
Authored by Shalom Carmel

The LDAP service on an iSeries server can be used to enumerate the AS400 user profiles.

tags | advisory
SHA-256 | c2b8bdaf2439c1b48e6be48182c9ebeacfaefa836bef1783fbc6e7ad751c62b1

as400ldap.txt

Change Mirror Download
AS/400 LDAP user accounts disclosure

Overview
-------------
By default, a new iSeries server comes with a pre-installed directory
server,better known as an LDAP server.LDAP, or Lightweight
Directory Access Protocol, is the industry standard for enterprise
directory services, and forms the basis for many common directory
applications such as Microsoft Active Directory,iPlanet directory,
Oracle OID and others. On the AS400,this pre-installed service is
turned on by default, although it is not necessary for the regular
operations of the AS/400 server.
The LDAP service can be used to enumerate the AS400 user profiles.

The problem
----------------
The AS400 system projected backend has the ability to map OS/400
objects as entries within the LDAP-accessible directory tree.
The projected objects are LDAP representations of OS/400 objects
instead of actual entries stored in the LDAP server database.
So far, OS/400 user profiles are the only objects
being mapped or projected as entries within the directory tree.
It is sufficient to retrieve the list of users with an LDAP search.
To conduct such a search, you need any valid AS/400 account.
The LDAP search ability is not dependant on any restrictions or
special permissions the user may have.
The search returns information about user profiles that are in the
same group like the account we use for the exploit, and this situation
is common enough in the legacy applications world.


Vulnerable versions:
------------------------
OS400 version 5.2 and up.

Workaround
----------------
Turn LDAP off. You probably do not need it.


References
http://publib.boulder.ibm.com/iseries/v5r2/ic2924/info/rzahy/rzahyldapops.htm


For full details and sample code please read the PDF file found at
http://www.venera.com/downloads

Shalom Carmel

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close