portswigger pathTraversal

lab1: File path traversal, simple case

展示图片处参数可控

https://0a2300e3039e268d80068f9f001800e4.web-security-academy.net/image?filename=38.jpg

尝试路径穿越

portswigger pathTraversal_第1张图片

lab2: File path traversal, traversal sequences blocked with absolute path bypass

portswigger pathTraversal_第2张图片

直接用绝对路径

lab3: File path traversal, traversal sequences stripped non-recursively

由于并不进行递归的替换 双写即可

portswigger pathTraversal_第3张图片

lab4: File path traversal, traversal sequences stripped with superfluous URL-decode

存在多次url解码 我们多次编码即可

portswigger pathTraversal_第4张图片

lab5: File path traversal, validation of start of path

限定前部分必须是/var/www/images/ 直接穿越即可

portswigger pathTraversal_第5张图片

lab6: File path traversal, validation of file extension with null byte bypass

限定扩展名

用%00绕过

portswigger pathTraversal_第6张图片

你可能感兴趣的:(网络安全,安全)