A penetration tester is trying to get unauthorized access to a web application and executes the following command:
GET /foo/images/file?id=2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd
Which of the following web application attacks is the tester performing?
The attacker is attempting to access restricted files by navigating directories beyond their intended scope.
Directory Traversal (Option C):
The request uses encoded '../' sequences (%2e%2e%2f = ../) to move up directories and access /etc/passwd.
This is a classic directory traversal attack aimed at accessing system files.
Incorrect options:
Option A (Insecure Direct Object Reference - IDOR): IDOR exploits direct access to objects (e.g., changing user_id=123 to user_id=456), not directory navigation.
Option B (CSRF): CSRF forces users to execute unwanted actions, unrelated to directory access.
Tarra
9 months agoHannah
9 months agoLenna
9 months agoLaquanda
10 months agoAlesia
10 months agoAn
10 months agoGeorgeanna
10 months agoMignon
11 months agoTyisha
11 months agoHarrison
11 months agoBrendan
11 months agoTruman
11 months agoCecil
11 months agoVeronika
1 year agoMose
1 year agoMatt
1 year agoEttie
1 year agoCiara
1 year agoKaycee
1 year agoYuki
1 year agoDenae
1 year agoSalley
1 year agoCeola
1 year agoLaurena
1 year agoElden
1 year agoLatonia
1 year agoJamal
1 year agoSamuel
1 year agoNobuko
1 year agoGracia
1 year agoMartha
1 year agoKristeen
1 year ago