Detecting Path Traversal Vulnerabilities
Having identified the various potential targets for path traversal testing,
you need to test every instance individually to determine whether user-
controllable data is being passed to relevant file system operations in an
unsafe manner.
For each user-supplied parameter being tested, determine whether traversal
sequences are being blocked by the application or whether they work as
expected. An initial test that is usually reliable is to submit traversal sequences
in a way that does not involve stepping back above the starting directory.
HACK STEPS
■
Do'stlaringiz bilan baham: |