<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ldap on bokkapig</title><link>https://bokkapig.pages.dev/tags/ldap/</link><description>Recent content in Ldap on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Tue, 18 Nov 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/ldap/index.xml" rel="self" type="application/rss+xml"/><item><title>Baby</title><link>https://bokkapig.pages.dev/writeups/baby/</link><pubDate>Tue, 18 Nov 2025 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/baby/</guid><description>LDAP anonymous bind leaks an initial password in a user description; the target user (Caroline.Robinson) has STATUS_PASSWORD_MUST_CHANGE set, allowing password reset via SAMR; Backup Operators group membership enables direct flag read via FILE_OPEN_FOR_BACKUP_INTENT over SMB.</description></item></channel></rss>