Directory traversal

A correctly implemented TFTP server confines requests to its root directory. Where it does not, filenames containing traversal sequences reach files elsewhere on the host, turning a limited file server into arbitrary file read (and, with write enabled, write) of system files outside the TFTP directory.

bash
tftp <target>
tftp> get ../../../../etc/passwd loot_passwd
tftp> get ..\..\..\..\windows\win.ini loot_winini   # Windows TFTP servers

Exploitation notes#

  • Try both ../ and ..\ separators depending on the server's platform, and repeat the sequence well past the expected depth.
  • Target /etc/passwd and service configs on Unix, and known config and credential files on Windows TFTP implementations.
  • Where write is also unconfined, traversal plus PUT is an arbitrary file write, reaching cron, startup, or web paths.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more