EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy

A security analyst is reviewing network traffic to a web server and observes several HTTP GET requests for non-existent files with repeated patterns like `../../../../etc/passwd`. The server responds with 404 Not Found errors for these requests. Which attack technique is the analyst most likely observing?

  1. ASQL Injection
  2. BCross-Site Scripting (XSS)
  3. CDirectory Traversal
  4. DOS Command Injection
Show answer & explanation

Correct answer: C. Directory Traversal

The pattern `../../../../etc/passwd` is a classic signature for Directory Traversal attempts, where an attacker tries to access files outside the intended web root directory by manipulating file paths.

Why the other options are wrong

  • A. SQL Injection targets databases with SQL commands, not file paths.
  • B. XSS involves injecting client-side scripts into web pages, not requesting server files.
  • D. OS Command Injection executes arbitrary operating system commands, which is distinct from path manipulation.

Directory Traversal

Directory Traversal (also known as Path Traversal) is a web security vulnerability that allows an attacker to read arbitrary files on the server running an application.

  • Achieved by manipulating input parameters that refer to file paths.
  • Uses characters like `../` or `..\` to navigate directory structures.
  • Can lead to disclosure of sensitive information like configuration files or source code.

Memory trick: Paths Peek Past Permissions.

More Web Application Hacking questions