Path Traversal
Lots of applications serve files chosen by the user: download an invoice, view an avatar, load a template. If the application builds a file path out of user input and trusts it, the user can supply a path that climbs out of the intended directory and reads files the application never meant to expose. This exercise explains the mechanism and the standard defence.
Log in or create a free account to submit keys and track your progress.
What you will learn
- Explain how the filesystem tree lets a relative path leave a folder
- Understand why user-controlled filenames are dangerous
- Recognise path traversal in an app and in source code
- Explain the fix: resolve the path and confirm it stays inside the allowed directory
Before you start
These exercises cover what this one builds on.
In this exercise
- The filesystem is a tree
- A filename from the user
- Recognising it
- The fix: confirm the path stays inside
🔒
This is a Pro exercise
Pro unlocks every exercise, the written solutions, the video walkthroughs and badge certificates. Free exercises stay free.
See Pro plans Create a free account4 sections · 2 keys · 50 points