Module 10: Directory Traversal Attacks
Directory Traversal Overview
Accessing The Lab Machines
Understanding Suggestive Parameters
GET /search/Hello%20World! HTTP/1.1GET /admin/dashboard/manage/handler.aspx?file=ourFile.jpeg HTTP/1.1?file=
?f=
/file/someFile
?location=
?l=
/location/someLocation
search=
s=
/search/someSearch
?data=
?d=
/data/someData
?download=
?d=
/download/someFileDataRelative vs. Absolute Pathing
Absolute Pathing
Extra Mile I
Relative Pathing
Extra Mile II
Directory Listing
Parameter Analysis

Evidence of Directory Listing




Directory Traversal Sandbox
Directory Traversal - Exploitation



Wordlist/Payload Lists
Fuzzing the Path Parameter
Case Study: Home Assistant
Initial Application Assessment


Exploitation



Extra Mile
Wrapping Up
Last updated