LanDscAPe: Exploring LDAP weaknesses and data leaks at Internet scale
Jonas Kaspereit, Gurur Öndarö, Gustavo Luvizotto Cesar, Simon Ebbers, Fabian Ising, Christoph Saatjohann, Mattijs Jonker, Ralph Holz, Sebastian Schinzel
摘要
The Lightweight Directory Access Protocol (LDAP) is the standard technology to query information stored in directories. These directories can contain sensitive personal data such as usernames, email addresses, and passwords. LDAP is also used as a central, organization-wide storage of configuration data for other services. Hence, it is important to the security posture of many organizations, not least because it is also at the core of Microsoft's Active Directory, and other identity management and authentication services. We report on a large-scale security analysis of deployed LDAP servers on the Internet. We developed LanDscAPe, a scanning tool that analyzes security-relevant misconfigurations of LDAP servers and the security of their TLS configurations. Our Internet-wide analysis revealed more than 10k servers that appear susceptible to a range of threats, including insecure configurations, deprecated software with known vulnerabilities, and insecure TLS setups. 4.9k LDAP servers host personal data, and 1.8k even leak passwords. We document, classify, and discuss these and briefly describe our notification campaign to address these concerning issues.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- S/MINE: Collecting and Analyzing S/MIME Certificates at ScaleGurur Öndarö, Jonas Kaspereit, Samson Umezulike, Christoph Saatjohann 等USENIX Security 2025
- LEAKYLINKS: Measuring the Security and Privacy Risks of URL Scanning ServicesAli Mustafa, Jannis Rautenstrauch, Florian Hantke, Shubham Agarwal 等S&P 2026
它引用的顶会 Paper4
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar 等NDSS 2016 · 被引用 117 次
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 被引用 114 次
- LZR: Identifying Unexpected Internet ServicesLiz Izhikevich, Renata Teixeira, Zakir DurumericUSENIX Security 2021 · 被引用 63 次
- Why TLS is better without STARTTLS: A Security Analysis of STARTTLS in the Email ContextDamian Poddebniak, Fabian Ising, Hanno Böck, Sebastian SchinzelUSENIX Security 2021 · 被引用 25 次
相关 Paper
- Exploring the Unknown DTLS Universe: Analysis of the DTLS Server Ecosystem on the InternetNurullah Erinola, Marcel Maehren, Robert Merget, Juraj Somorovsky 等USENIX Security 2023
- ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS AuthenticationMarcus Brinkmann, Christian Dresen, Robert Merget, Damian Poddebniak 等USENIX Security 2021 · 被引用 20 次
- Automatic Insecurity: Exploring Email Auto-configuration in the WildShushang Wen, Yiming Zhang, Yuxiang Shen, Bingyu Li 等NDSS 2025
- A Multifaceted Study on the Use of TLS and Auto-detect in Email EcosystemsKa Fun Tang, Che Wei Tu, Sui Ling Angela Mak, Sze Yiu ChauNDSS 2025
- A Large-Scale Measurement Study of the PROXY Protocol and its Security ImplicationsStijn Pletinckx, Christopher Kruegel, Giovanni VignaNDSS 2025
