Directory Traversal - Lab #4 Path traversal sequences stripped w/ URL-decode | Long Version

Опубликовано: 09 Октябрь 2024
на канале: Rana Khalil
2,134
71

In this video, we cover Lab #4 in the Directory Traversal Vulnerabilities module of the Web Security Academy. This lab contains a file path traversal vulnerability in the display of product images. The application blocks input containing path traversal sequences. It then performs a URL-decode of the input before using it. To solve the lab, we retrieve the contents of the /etc/passwd file.

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://academy.ranakhalil.com/p/web-...

▬ 📚 Contents of this video 📚 ▬▬▬▬▬▬▬▬▬▬
00:00​​​ - Introduction
00:16 - Web Security Academy Course (https://bit.ly/30LWAtE)
01:26 - Navigation to the exercise
02:01 - Understand the exercise and make notes about what is required to solve it
02:51 - Exploit the lab
05:59 - Script the exploit in Python
13:15 - Summary
13:30 - Thank You

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Python script: https://github.com/rkhal101/Web-Secur...
Web Security Academy Exercise Link: https://portswigger.net/web-security/...
Rana's Twitter account:   / rana__khalil