Saturday, 30 May 2015

Web for Pentester - Directory Traversal

There are 3 Examples to complete.

Viewing the Source shows these better.



1. No real issues.


2. A different approach, as the first method didnt work.

  

3. This was much harder, after trying a few options, i decided to employ DotDotPwn to find it.

 perl dotdotpwn.pl -m http-url -h 192.168.56.101 -u http://192.168.56.101/dirtrav/example3.php?file=TRAVERSAL -o unix -b -k root



Found! 
Now to test it in a browser.



Further Reading can be found here:



Thanks for reading.


No comments:

Post a Comment