How To Exploit Directory Traversal Vulnerability

SHARE:

Backtrack has lots of tools for web-application testing. Directory traversal is one of the critical vulnerability in web-application. In bactrack automatic tools are available for this test which is DOTDOTPWN.

If you are on other distro , then you can download it form here.

It's a very flexible intelligent fuzzer to discover traversal directory vulnerabilities in software such as HTTP/FTP/TFTP servers, Web platforms such as CMSs, ERPs, Blogs, etc. 

Also, it has a protocol-independent module to send the desired payload to the host and port specified. On the other hand, it also could be used in a scripting way using the STDOUT module.

It's written in perl programming language and can be run either under *NIX or Windows platforms. It's the first Mexican tool included in BackTrack Linux .


Fuzzing Modules Supported In This Version:


- HTTP

- HTTP URL

- FTP

- TFTP

- Payload (Protocol independent)

- STDOUT

./dotdotpwn.pl -m  http-url -S -u https://localhost/mutillidae/index.php?page=TRAVERSAL -k root -o unix    
path-traversal

In below figure; you can see vulnerable URL where directory traversal is applicable.
path-traversal

COMMENTS

Name

11th,2,12th,20,12th Chemistry,5,12th Computer Science,7,12th Physics,1,5th Sem CSE,1,AAI ATC,2,Android,18,Banking,1,Blogger,41,Books,5,BTech,17,CBSE,22,CSE,4,ECE,3,Electronics,1,English,2,ESE,1,Ethical Hacking,61,Exams,5,Games,9,GATE,1,GATE ECE,1,Government Jobs,1,GS,1,How To,27,IBPS PO,1,Information,52,Internet,24,IPU,8,JEE,8,JEE Mains,8,Jobs,1,Linux,65,News,18,Notes,23,Physics,3,Placement,10,PO,1,Poetry,3,RRB,1,SEO,11,Softwares,38,SSC,2,SSC CGL,1,SSC GS,2,Tips and Tricks,46,UPSC,1,Windows,46,
ltr
item
SolutionRider- One Stop Solution for Notes, Exams Prep, Jobs & Technical Blogs.: How To Exploit Directory Traversal Vulnerability
How To Exploit Directory Traversal Vulnerability
Backtrack has lots of tools for web-application testing. Directory traversal is one of the critical vulnerability in web-application. In bactrack automatic tools are available for this test which is DOTDOTPWN. If you are on other distro , then you can download it form here. It's a very flexible intelligent fuzzer to discover traversal directory vulnerabilities in software such as HTTP/FTP/TFTP servers, Web platforms such as CMSs, ERPs, Blogs, etc. Also, it has a protocol-independent module to send the desired payload to the host and port specified. On the other hand, it also could be used in a scripting way using the STDOUT module. It's written in perl programming language and can be run either under *NIX or Windows platforms. It's the first Mexican tool included in BackTrack Linux . Fuzzing Modules Supported In This Version: - HTTP - HTTP URL - FTP - TFTP - Payload (Protocol independent) - STDOUT ./dotdotpwn.pl -m http-url -S -u https://localhost/mutillidae/index.php?page=TRAVERSAL -k root -o unix path-traversal In below figure; you can see vulnerable URL where directory traversal is applicable. path-traversal
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJIR4TPej9ZMbIuTebY1Piw9m8rSW4gc9x3j1XVmzBnhPqgDCEyUdjcyJgFq-PWcJG1YRMlaDXsFO2Xp4PzPT4DACTCsg3iws9vWcTIZ4KWXmwDT_TAFMEPv1hknPTuccRFwBu-b3X0G5Q/s640/Path-traversal.PNG
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJIR4TPej9ZMbIuTebY1Piw9m8rSW4gc9x3j1XVmzBnhPqgDCEyUdjcyJgFq-PWcJG1YRMlaDXsFO2Xp4PzPT4DACTCsg3iws9vWcTIZ4KWXmwDT_TAFMEPv1hknPTuccRFwBu-b3X0G5Q/s72-c/Path-traversal.PNG
SolutionRider- One Stop Solution for Notes, Exams Prep, Jobs & Technical Blogs.
https://thesolutionrider.blogspot.com/2017/10/how-to-exploit-directory-traversal.html
https://thesolutionrider.blogspot.com/
https://thesolutionrider.blogspot.com/
https://thesolutionrider.blogspot.com/2017/10/how-to-exploit-directory-traversal.html
true
6820083649286484786
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy