LDAP Injection: When User Input Rewrites a Directory Search
LDAP injection is SQL injection's directory-service cousin. Learn how unescaped assertion values rewrite a search filter, why password checks belong in a bind, and how RFC 4515 encoding closes the boundary.