LDAP Injection
Resources on Constructing LDAP Queries
LDAP Filter Syntax - Cheatsheet
LDAP Injection Cheatsheet
PayloadAllTheThings - LDAP Injection
userPassword
attribute is not a string like thecn
attribute for example but itβs an OCTET STRING In LDAP, every object, type, operator etc. is referenced by an OID : octetStringOrderingMatch (OID 2.5.13.18).