Prevention
Escaping Special Characters
PHP Example (filter-based auth)
$filter = '(&(cn=' . $_POST['username'] . ')(userPassword=' . $_POST['password'] . '))';$filter = '(&(cn=' . ldap_escape($_POST['username']) . ')(userPassword=' . ldap_escape($_POST['password']) . '))';Prefer Bind-Based Authentication
Best Practices
References
Last updated