What is File Path Traversal? Stealing the contents of the /etc/passwd file...

preview_player
Показать описание
In this video we'll answer the question 'What is File Path Traversal?'

It's a type of web security vulnerability that allows arbitrary read access on directories that should not be available to an end user.

In this lab we exploit vulnerable web images to steal the contents of the /etc/passwd file as proof of concept.

This content is provided free of charge. Buy me a coffee though!
Please like and subscribe, it means a lot!

00:00 Intro
00:33 Why etc/passwd ?
01:15 Analysing the vulnerables images
03:21 Exploiting file path traversal vulnerability
05:13 Analysing the browser response to /etc/passwd request
06:55 Inspecting the response in Burp suite
08:11 Accessing the /etc/passwd through the browser
10:51 Summary
Рекомендации по теме
Комментарии
Автор

Very clean explanation. I appreciate you going more in-depth at the end to go beyond just what port swigger is discussing.

HundredAcres
Автор

1) After such a beautiful explanation, how do I make the website show that I "passed" the lab?
2) Second thing - how do I fix this weakness on the website?

לומדטסטר
Автор

We forever locked in brother I need videos after reading for it to stick

beamboyz
Автор

simple explain by these method web, burp, image.txt thanks

eyesoffloraandfauna