Path traversal (also known as directory traversal) vulnerabilities enable an attacker to interact with arbitrary files on the server, giving them access to sensitive data. If they can also write to these files, they can potentially modify application data or behavior, ultimately taking full control of the server.
These vulnerabilities allow an attacker to read arbitrary files on the server running the application. This might include:
Application code and data.
Credentials for back-end systems.
Sensitive operating system files.
Visit and complete the original lab on PortSwigger's website
New to Burp Suite? Learn how to set up Burp Suite for the first time.
LAB
This lab contains a path traversal vulnerability in the display of product images.
To solve the lab, retrieve the contents of the /etc/passwd file.
Steps to solve the LAB:
Open Burp Suite and Start the Lab:
Open Burp Suite, a web vulnerability scanner, and ensure that the intercept feature is turned ON
Start the lab by navigating to the provided URL.
Intercept a Request:
Click on any product in the online shop page. This action typically triggers a request to fetch the product's image.
3. Modify the Request:
Use Burp Suite to intercept this request. Look for the part of the request URL that includes the image filename parameter.
Modify the filename parameter, giving it the value: ../../../etc/passwd
Why this works: The ../ sequence tells the server to move up one directory level. By chaining three of these sequences together (../../../), we move up three levels in the directory structure, effectively navigating out of the web directory and into the root directory of the server's filesystem. The final part, etc/passwd, specifies the target file to be read.
4. Send the Modified Request:
Forward the modified request from Burp Suite to the server.
5. Analyze the Response:
Go to the HTTP history tab in Burp Suite and find the response to your modified request.
Observe that the response contains the contents of the /etc/passwd file.
Why this is important: The /etc/passwd file contains user account information, which could include usernames and other details that might be leveraged for further attacks. Successfully retrieving this file demonstrates that the path traversal vulnerability allows access to sensitive data outside the intended directory.
Mastering the ability to navigate the directory structure using ../ sequences is crucial for exploiting path traversal vulnerabilities. This knowledge allows attackers to move up and down the directory tree, accessing files outside the intended directory.
This lab underscores the critical need for proper input validation and sanitization to prevent unauthorized access to files. Ensuring that user inputs are strictly controlled can help mitigate such vulnerabilities.
Accessing sensitive files like /etc/passwd can lead to significant security breaches. This highlights the importance of securing web applications against path traversal attacks to protect sensitive data and maintain overall system integrity.
By following these steps, you gain practical experience in identifying and exploiting path traversal vulnerabilities, an essential skill for web security professionals. This hands-on knowledge equips you to better understand and defend against real-world security threats.