<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP backdoor? in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ldap-backdoor/m-p/72727#M47324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi there,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am new to Alfresco and trying to set up a staging server for testing.&amp;nbsp; I have the server up without any problem.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Howerver, when i looked at the LDAP log. I found that there is a false binding attamp every time when the server was started.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Have anyone noticed the same issue? Is this some kind of backdoor put by a programer?&amp;nbsp; I can't find the setting anywhere in the setting files.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt; [quote]&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: bind: invalid dn (daftAsABrush)&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=57 op=0 RESULT tag=97 err=34 text=invalid DN&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=58 fd=21 ACCEPT from IP=127.0.0.1:33436 (IP=0.0.0.0:389)&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=57 fd=20 closed&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=58 op=0 BIND dn="cn=daftAsABrush,dc=woof" method=128&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=58 op=0 RESULT tag=97 err=49 text=&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=59 fd=20 ACCEPT from IP=127.0.0.1:33437 (IP=0.0.0.0:389)&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=58 fd=21 closed&lt;BR /&gt;(following is my own setting)&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=59 op=0 BIND dn="cn=Alfresco,dc=xxxxxx,dc=xxxxx" method=128&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=59 op=0 RESULT tag=97 err=49 text=&lt;BR /&gt;Jan 11 10:09:29 stg slapd[1468]: conn=59 fd=20 closed&lt;BR /&gt;Jan 11 10:09:30 stg slapd[1468]: conn=56 op=1 UNBIND&lt;BR /&gt;Jan 11 10:09:30 stg slapd[1468]: conn=56 fd=19 closed&lt;BR /&gt;[/quote]&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Jan 2007 08:44:36 GMT</pubDate>
    <dc:creator>chsieh</dc:creator>
    <dc:date>2007-01-11T08:44:36Z</dc:date>
    <item>
      <title>LDAP backdoor?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-backdoor/m-p/72727#M47324</link>
      <description>Hi there,I am new to Alfresco and trying to set up a staging server for testing.&amp;nbsp; I have the server up without any problem.Howerver, when i looked at the LDAP log. I found that there is a false binding attamp every time when the server was started.Have anyone noticed the same issue? Is this some kin</description>
      <pubDate>Thu, 11 Jan 2007 08:44:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-backdoor/m-p/72727#M47324</guid>
      <dc:creator>chsieh</dc:creator>
      <dc:date>2007-01-11T08:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP backdoor?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-backdoor/m-p/72728#M47325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This is checking to see if the LDAP server will fall back to anoymous bind in a number of circumstances. If this is the case then the LDAP server will not be used. It is difficult to detect this and revert back to giving only guest access to the app. Unless you know how to get the real uid of the bound user as opposed to the one provided in the bind request … &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Jan 2007 12:00:46 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-backdoor/m-p/72728#M47325</guid>
      <dc:creator>andy</dc:creator>
      <dc:date>2007-01-11T12:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP backdoor?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-backdoor/m-p/72729#M47326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks a lot Andy!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2007 03:01:16 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-backdoor/m-p/72729#M47326</guid>
      <dc:creator>chsieh</dc:creator>
      <dc:date>2007-01-12T03:01:16Z</dc:date>
    </item>
  </channel>
</rss>

