On this page
apsyleg1 min read
#portswigger #path-traversal #web-security
File Path Traversal: Non-Recursive Stripping of Traversal Sequences
Lab
File path traversal, traversal sequences stripped non-recursively · Apprentice
Solution
Given
This lab contains a path traversal vulnerability in the display of product images.
The application strips path traversal sequences from the user-supplied filename before using it.
To solve the lab, retrieve the contents of the /etc/passwd file.
Analysis and recon
Same as the previous lab, except this time the app removes ../ but not recursively.
Final payload
GET /image?filename=....//....//....//etc/passwd
More in this category
Arbitrary Object Injection in PHP (PortSwigger Lab)
Recovering leaked source code and injecting a serialized CustomTemplate object whose __destruct deletes an arbitrary file.
Using Application Functionality to Exploit Insecure Deserialization (PortSwigger Lab)
Tampering with the `avatar_link` field in the session object to delete an arbitrary file via the account-delete feature.
Modifying Serialized Data Types (PortSwigger Lab)
Abusing PHP loose comparison by changing the `access_token` type to integer `0` to bypass authentication.