CAPEC-126
Path Traversal
An adversary uses path manipulation methods to exploit insufficient input validation of a target to obtain access to data that should be not be retrievable by ordinary well-formed requests. A typical variety of this attack involves specifying a path to a desired file together with dot-dot-slash characters, resulting in the file access API or function traversing out of the intended directory structure and into the root file system. By replacing or modifying the expected path information the access function or API retrieves the file desired by the attacker. These attacks either involve the attacker providing a complete path to a targeted file or using control characters (e.g. path separators (/ or \) and/or dots (.)) to reach desired directories or files.
Soyutlama
Standard
Tipik ciddiyet
Very High
Saldırı ihtimali
High
Saldırıyı anla
Bu saldırı kalıbı nedir?
Uygulama akışı
Saldırı adım adım nasıl ilerler?
Explore
Fingerprinting of the operating system
Kullanılan teknikler
- Port mapping. Identify ports that the system is listening on, and attempt to identify inputs and protocol types on those ports.
- TCP/IP Fingerprinting. The attacker uses various software to make connections or partial connections and observe idiosyncratic responses from the operating system. Using those responses, they attempt to guess the actual operating system.
- Induce errors to find informative error messages
Survey the Application to Identify User-controllable Inputs
Experiment
Vary inputs, looking for malicious results
Exploit
Manipulate files accessible by the application
Gereksinimler
Saldırının gerçekleşmesi için ne gerekir?
Ön koşullar
- The attacker must be able to control the path that is requested of the target.
- The target must fail to adequately sanitize incoming paths
Gerekli beceri
- Low: Simple command line attacks or to inject the malicious payload in a web page.
- Medium: Customizing attacks to bypass non trivial filters in the application.
Gerekli kaynak
- The ability to manually manipulate path information either directly through a client application relative to the service or application or via a proxy application.
Etki
Başarılı saldırı neye yol açar?
Etkilenen alanlar: Integrity, Confidentiality, Availability
Etkilenen alanlar: Integrity
Etkilenen alanlar: Confidentiality
Etkilenen alanlar: Availability
Savunma
Nasıl önlenir ve etkisi azaltılır?
Gerçek dünya