CAPEC-126
Path Traversal
An adversary uses path manipulation methods to exploit insufficient input validation of a target to obtain access to data that should be not be retrievable by ordinary well-formed requests. A typical variety of this attack involves specifying a path to a desired file together with dot-dot-slash characters, resulting in the file access API or function traversing out of the intended directory structure and into the root file system. By replacing or modifying the expected path information the access function or API retrieves the file desired by the attacker. These attacks either involve the attacker providing a complete path to a targeted file or using control characters (e.g. path separators (/ or \) and/or dots (.)) to reach desired directories or files.
Abstraction
Standard
Typical severity
Very High
Likelihood of attack
High
Understand the attack
What is this attack pattern?
Execution flow
How does the attack proceed, step by step?
Explore
Fingerprinting of the operating system
Techniques used
- Port mapping. Identify ports that the system is listening on, and attempt to identify inputs and protocol types on those ports.
- TCP/IP Fingerprinting. The attacker uses various software to make connections or partial connections and observe idiosyncratic responses from the operating system. Using those responses, they attempt to guess the actual operating system.
- Induce errors to find informative error messages
Survey the Application to Identify User-controllable Inputs
Experiment
Vary inputs, looking for malicious results
Exploit
Manipulate files accessible by the application
Requirements
What does the attack require?
Prerequisites
- The attacker must be able to control the path that is requested of the target.
- The target must fail to adequately sanitize incoming paths
Skills required
- Low: Simple command line attacks or to inject the malicious payload in a web page.
- Medium: Customizing attacks to bypass non trivial filters in the application.
Resources required
- The ability to manually manipulate path information either directly through a client application relative to the service or application or via a proxy application.
Impact
What does a successful attack lead to?
Affected scopes: Integrity, Confidentiality, Availability
Affected scopes: Integrity
Affected scopes: Confidentiality
Affected scopes: Availability
Defence
How is it prevented and mitigated?
Real world