EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy
A penetration tester is evaluating a web application that uses URL parameters to control content display. They observe that a parameter named `page` is used to load different HTML files (e.g., `example.com/app?page=home.html`). The tester attempts to manipulate this parameter to access sensitive files outside the intended directory, such as `example.com/app?page=../../../../etc/passwd`. Which type of web application attack is being attempted?
- ACross-Site Scripting (XSS)
- BServer-Side Request Forgery (SSRF)
- CSQL Injection
- DDirectory Traversal
Show answer & explanationAnswer & explanation
Correct answer: D. Directory Traversal
The scenario describes an attacker manipulating URL parameters to access files outside the intended directory structure, which is the definition of a Directory Traversal attack. This attack exploits vulnerabilities in how web servers handle file paths.
Why the other options are wrong
- A. Cross-Site Scripting involves injecting malicious scripts into web pages viewed by other users.
- B. SSRF forces the server to make requests to internal or external resources on behalf of the attacker, not directly accessing local file paths in this manner.
- C. SQL Injection targets databases, not file system access.
Directory Traversal
A web application vulnerability that allows an attacker to read arbitrary files on the web server by manipulating file paths in URLs or other input fields.
- Also known as Path Traversal.
- Exploits insufficient validation of user-supplied input.
- Can lead to disclosure of sensitive information like configuration files or password files.
Memory trick: Path to the 'passwd' leads to trouble.