EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingEasy
A security analyst is reviewing network traffic to a web server and observes several HTTP GET requests for non-existent files with repeated patterns like `../../../../etc/passwd`. The server responds with 404 Not Found errors for these requests. Which attack technique is the analyst most likely observing?
- ASQL Injection
- BCross-Site Scripting (XSS)
- CDirectory Traversal
- DOS Command Injection
Show answer & explanationAnswer & explanation
Correct answer: C. Directory Traversal
The pattern `../../../../etc/passwd` is a classic signature for Directory Traversal attempts, where an attacker tries to access files outside the intended web root directory by manipulating file paths.
Why the other options are wrong
- A. SQL Injection targets databases with SQL commands, not file paths.
- B. XSS involves injecting client-side scripts into web pages, not requesting server files.
- D. OS Command Injection executes arbitrary operating system commands, which is distinct from path manipulation.
Directory Traversal
Directory Traversal (also known as Path Traversal) is a web security vulnerability that allows an attacker to read arbitrary files on the server running an application.
- Achieved by manipulating input parameters that refer to file paths.
- Uses characters like `../` or `..\` to navigate directory structures.
- Can lead to disclosure of sensitive information like configuration files or source code.
Memory trick: Paths Peek Past Permissions.