CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard

A penetration tester crafts the following input for a corporate directory search field: *)(uid=*))(|(uid=*. After submission, the application returns all user records instead of just the intended search result. Which type of injection attack does this represent?

  1. ASQL injection
  2. BLDAP injection
  3. CCommand injection
  4. DXML injection
Show answer & explanation

Correct answer: B. LDAP injection

LDAP injection manipulates LDAP query filters using special characters such as parentheses, asterisks, and pipe symbols to alter the logic of directory service queries, often bypassing filters to return unauthorized data. The crafted string uses LDAP filter syntax (uid=*, parentheses, and the OR operator |) to exploit an improperly sanitized directory search.

Why the other options are wrong

  • A. SQL injection targets relational database query syntax like quotes and SQL keywords, not LDAP filters.
  • C. Command injection targets OS shell commands, not directory service query filters.
  • D. XML injection targets XML parsers using tags and entities, not LDAP filter syntax.

LDAP Injection

An attack that manipulates LDAP (Lightweight Directory Access Protocol) query filters by injecting special characters to alter search logic and bypass access controls.

  • Exploits parentheses, asterisks, and boolean operators in filters
  • Can bypass authentication or dump directory data
  • Mitigated by input sanitization and parameterized LDAP queries

Memory trick: LDAP filters use ()* like SQL uses quotes—same trick, different syntax.

More Threats, Vulnerabilities, and Mitigations questions