A correctly implemented TFTP server confines requests to its root directory. Where it does not, filenames containing traversal sequences reach files elsewhere on the host, turning a limited file server into arbitrary file read (and, with write enabled, write) of system files outside the TFTP directory.
tftp <target>
tftp> get ../../../../etc/passwd loot_passwd
tftp> get ..\..\..\..\windows\win.ini loot_winini # Windows TFTP servers
Exploitation notes#
- Try both
../and..\separators depending on the server's platform, and repeat the sequence well past the expected depth. - Target
/etc/passwdand service configs on Unix, and known config and credential files on Windows TFTP implementations. - Where write is also unconfined, traversal plus PUT is an arbitrary file write, reaching cron, startup, or web paths.