A penetration tester is trying to get unauthorized access to a web application and executes the following command:
GET /foo/images/file?id=2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd
Which of the following web application attacks is the tester performing?
The attacker is attempting to access restricted files by navigating directories beyond their intended scope.
Directory Traversal (Option C):
The request uses encoded '../' sequences (%2e%2e%2f = ../) to move up directories and access /etc/passwd.
This is a classic directory traversal attack aimed at accessing system files.
Incorrect options:
Option A (Insecure Direct Object Reference - IDOR): IDOR exploits direct access to objects (e.g., changing user_id=123 to user_id=456), not directory navigation.
Option B (CSRF): CSRF forces users to execute unwanted actions, unrelated to directory access.
Tarra
2 months agoHannah
2 months agoLenna
3 months agoLaquanda
3 months agoAlesia
3 months agoAn
3 months agoGeorgeanna
4 months agoMignon
4 months agoTyisha
4 months agoHarrison
4 months agoBrendan
4 months agoTruman
5 months agoCecil
5 months agoVeronika
11 months agoMose
10 months agoMatt
10 months agoEttie
10 months agoCiara
11 months agoKaycee
9 months agoYuki
9 months agoDenae
10 months agoSalley
10 months agoCeola
11 months agoLaurena
11 months agoElden
11 months agoLatonia
10 months agoJamal
10 months agoSamuel
10 months agoNobuko
11 months agoGracia
11 months agoMartha
11 months agoKristeen
11 months ago