syurhia 님의 블로그

File path traversal 순서 정리 본문

보안관련/PortSwigger

File path traversal 순서 정리

syurhia 2026. 5. 29. 21:22

1. File path traversal, simple case

 

2. File path traversal, traversal sequences blocked with absolute path bypass

 

3. File path traversal, traversal sequences stripped non-recursively

 

4. File path traversal, traversal sequences stripped with superfluous URL-decode

 

5. File path traversal, validation of start of path

 

6. File path traversal, validation of file extension with null byte bypass

 

7. File path traversal 막는 방법