Path Traversal

🔒 Pro Medium Course Online Avg. time 25 min Solved by 0 2 keys · 50 pts Injection Server-Side Attacks

Lots of applications serve files chosen by the user: download an invoice, view an avatar, load a template. If the application builds a file path out of user input and trusts it, the user can supply a path that climbs out of the intended directory and reads files the application never meant to expose. This exercise explains the mechanism and the standard defence.

Log in or create a free account to submit keys and track your progress.

What you will learn

  • Explain how the filesystem tree lets a relative path leave a folder
  • Understand why user-controlled filenames are dangerous
  • Recognise path traversal in an app and in source code
  • Explain the fix: resolve the path and confirm it stays inside the allowed directory

Before you start

These exercises cover what this one builds on.

In this exercise

  1. The filesystem is a tree
  2. A filename from the user
  3. Recognising it
  4. The fix: confirm the path stays inside
🔒

This is a Pro exercise

Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.

See Pro plans Create a free account

4 sections · 2 keys · 50 points