CAPEC-139
Relative Path Traversal
An attacker exploits a weakness in input validation on the target by supplying a specially constructed path utilizing dot and slash characters for the purpose of obtaining access to arbitrary files or resources. An attacker modifies a known path on the target in order to reach material that is not available through intended channels. These attacks normally involve adding additional path separators (/ or \) and/or dots (.), or encodings thereof, in various combinations in order to reach parent directories or entirely separate trees of the target's directory structure.
Soyutlama
Detailed
Tipik ciddiyet
High
Saldırı ihtimali
High
Saldırıyı anla
Bu saldırı kalıbı nedir?
Uygulama akışı
Saldırı adım adım nasıl ilerler?
Explore
Fingerprinting of the operating system
Kullanılan teknikler
- Port mapping. Identify ports that the system is listening on, and attempt to identify inputs and protocol types on those ports.
- TCP/IP Fingerprinting. The adversary uses various software to make connections or partial connections and observe idiosyncratic responses from the operating system. Using those responses, they attempt to guess the actual operating system.
- Induce errors to find informative error messages
Survey application
Kullanılan teknikler
- Use a spidering tool to follow and record all links on a web page. Make special note of any links that include parameters in the URL.
- Use a proxy tool to record all links visited during a manual traversal of a web application. Make special note of any links that include parameters in the URL. Manual traversal of this type is frequently necessary to identify forms that are GET method forms rather than POST forms.
- Use a browser to manually explore a website and analyze how it is constructed. Many browser plug-ins are available to facilitate the analysis or automate the URL discovery.
Experiment
Attempt variations on input parameters
Kullanılan teknikler
- Provide "../" or "..\" at the beginning of any filename to traverse to the parent directory
- Use a list of probe strings as path traversal payload. Different strings may be used for different platforms. Strings contain relative path sequences such as "../".
- Use a proxy tool to record results of manual input of relative path traversal probes in known URLs.
Exploit
Access, modify, or execute arbitrary files.
Kullanılan teknikler
- Manipulate file and its path by injecting relative path sequences (e.g. "../").
- Download files, modify files, or try to execute shell commands (with binary files).
Gereksinimler
Saldırının gerçekleşmesi için ne gerekir?
Ön koşullar
- The target application must accept a string as user input, fail to sanitize combinations of characters in the input that have a special meaning in the context of path navigation, and insert the user-supplied string into path navigation commands.
Gerekli beceri
- Low: To inject the malicious payload in a web page
- High: To bypass non trivial filters in the application
Gerekli kaynak
MITRE kaydında belirtilmemiş.
Etki
Başarılı saldırı neye yol açar?
Etkilenen alanlar: Integrity
Etkilenen alanlar: Confidentiality
Etkilenen alanlar: Confidentiality, Integrity, Availability
Etkilenen alanlar: Access Control
Etkilenen alanlar: Availability
Savunma
Nasıl önlenir ve etkisi azaltılır?
Gerçek dünya