Directory Traversal

Definition - What does Directory Traversal mean?

Directory traversal is a security exploit within HTTP that enables an individual to access restricted files or directories and execute commands that are external to the Web server’s root directory. It is used to access restricted content or files on a Web server.

Directory traversal is also known as path traversal, . . / attack (dot dot slash attack), directory climbing and backtracking.

Techopedia explains Directory Traversal

Directory traversal is primarily a type of attack performed by a hacker or a cracker that induces the server to traverse to the parent directory or to expose server-specific controls. Directory traversal generally happens as a result of a lack of or insufficient validation within the code of the application hosted/executed on the Web server.

In a directory traversal, the hacker/cracker typically sends in an HTTP request with a series of ../, in order to traverse or climb to a parent directory. The application/server is unable to validate the input data from the Web browser and grants access to the internal and restricted directories and the data they contain. Once the cracker/hacker gains access to the parent directory, he or she can view, edit and delete files, or even execute specific commands.
Share this:

Connect with us

Email Newsletter

Join thousands of others with our weekly newsletter

The 4th Era of IT Infrastructure: Superconverged Systems
The 4th Era of IT Infrastructure: Superconverged Systems:
Learn the benefits and limitations of the 3 generations of IT infrastructure – siloed, converged and hyperconverged – and discover how the 4th...
Approaches and Benefits of Network Virtualization
Approaches and Benefits of Network Virtualization:
Businesses today aspire to achieve a software-defined datacenter (SDDC) to enhance business agility and reduce operational complexity. However, the...
Free E-Book: Public Cloud Guide
Free E-Book: Public Cloud Guide:
This white paper is for leaders of Operations, Engineering, or Infrastructure teams who are creating or executing an IT roadmap.
Free Tool: Virtual Health Monitor
Free Tool: Virtual Health Monitor:
Virtual Health Monitor is a free virtualization monitoring and reporting tool for VMware, Hyper-V, RHEV, and XenServer environments.
Free 30 Day Trial – Turbonomic
Free 30 Day Trial – Turbonomic:
Turbonomic delivers an autonomic platform where virtual and cloud environments self-manage in real-time to assure application performance.