vuLnDAP
Tool and Usage
Project details
- License
- GPLv3
- Programming language
- Golang
- Author
- Robin Wood
- Latest release
- No release found
- Latest release date
- Unknown
Project health
Why this tool?
VuLnDAP is a tool to show what can happen when a web application becomes vulnerable due to the business logic behind it. This tool uses LDAP, a common authentication protocol, to show such weaknesses. This tool helps penetration testers more about LDAP. At the same time, it provides useful insights to web and software developers to create more secure software.
How it works
The vuLnDAP tool provides a web server which the tester can use to attack the web application.
Background information
This project is the first Golang project by author Robin Wood. He created the tool after a request by Adrien de Beaupre to have a vulnerable LDAP target for the SANS 642 training.
Usage and audience
vuLnDAP is commonly used for application security, learning, or penetration testing. Target users for this tool are developers, pentesters, and security professionals.
Tool review and remarks
The review and analysis of this project resulted in the following remarks for this security tool:
Strengths
- + The source code of this software is available
Installation
Supported operating systems
VuLnDAP is known to work on Linux.
vuLnDAP alternatives
Similar tools to vuLnDAP:
Damn Small Vulnerable Web
Looking for a deliberately vulnerable application to test your exploitation skills? Learn in this review about the Damn Small Vulnerable Web project and how it can help.
Arachni
Web Application Security Scanner aimed towards helping users evaluate the security of web applications
LFI Suite
LFI Suite is a security tool to automate the scanning and exploitation of Local File Inclusion vulnerabilities. It uses a wide range of attack methods to achieve this goal. This tool would be useful to penetration testers for security assignments.
This tool page was updated at . Found an improvement? Help the community by submitting an update.
Related tool information
Categories
This tool is categorized as a vulnerable practice application.