Path traversal

HTTP file servers that build a filesystem path from user input and fail to normalize it allow traversal out of the served root. Sequences like ../, their encoded forms, and absolute paths reach files elsewhere on the host, turning the file server into arbitrary file read. This overlaps the web path-traversal class, applied to the file-serving feature.

bash
curl --path-as-is 'http://<target>/download?file=../../../../etc/passwd'
curl --path-as-is 'http://<target>/..%2f..%2f..%2fetc%2fpasswd'   # encoded

Exploitation notes#

  • Try raw, URL-encoded, double-encoded, and overlong UTF-8 traversal sequences, since filters often catch only the literal ../.
  • On Windows file servers, use ..\ and target known config and credential files.
  • The deeper treatment of traversal and its bypasses lives in the Web area; this is the file-server-specific application.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more