The LDAP Swiss Army Knife Server

Information security firm Packet Storm published a blog post about the LDAP Swiss Army Knife, a simple LDAP server (implemented using the UnboundID LDAP SDK for Java) that can be used for LDAP security-related testing, including intercepting plaintext credentials, forwarding NTLM credentials, and exploiting various LDAP-related vulnerabilities. They also posted a PDF document from pentesting firm SySS that describes a number of ways to use it for LDAP security-related testing.