EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy

A penetration tester is evaluating a web application that uses URL parameters to control content display. They observe that a parameter named `page` is used to load different HTML files (e.g., `example.com/app?page=home.html`). The tester attempts to manipulate this parameter to access sensitive files outside the intended directory, such as `example.com/app?page=../../../../etc/passwd`. Which type of web application attack is being attempted?

  1. ACross-Site Scripting (XSS)
  2. BServer-Side Request Forgery (SSRF)
  3. CSQL Injection
  4. DDirectory Traversal
Show answer & explanation

Correct answer: D. Directory Traversal

The scenario describes an attacker manipulating URL parameters to access files outside the intended directory structure, which is the definition of a Directory Traversal attack. This attack exploits vulnerabilities in how web servers handle file paths.

Why the other options are wrong

  • A. Cross-Site Scripting involves injecting malicious scripts into web pages viewed by other users.
  • B. SSRF forces the server to make requests to internal or external resources on behalf of the attacker, not directly accessing local file paths in this manner.
  • C. SQL Injection targets databases, not file system access.

Directory Traversal

A web application vulnerability that allows an attacker to read arbitrary files on the web server by manipulating file paths in URLs or other input fields.

  • Also known as Path Traversal.
  • Exploits insufficient validation of user-supplied input.
  • Can lead to disclosure of sensitive information like configuration files or password files.

Memory trick: Path to the 'passwd' leads to trouble.

More Web Application Hacking questions