← Back to Attack / Defense Lab
OSI LAYER 7 // Application Layer

Directory Traversal

Directory traversal is unauthorized access to files outside an application’s intended directory by manipulating path input.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

The application accepts a user-controlled path and fails to constrain it to an approved directory or canonicalize it safely.

02 // DETECTION

Indicators to watch

Repeated path-normalization failures, requests containing suspicious path patterns, access to configuration files, and unexpected file-read errors.

03 // ATTACK FLOW

Concept diagram

01File request↓
02Untrusted path↓
03Path resolution↓
04Unauthorized file access↓
05Canonicalization + ACLs
04 // PREVENTION

Defensive controls

Canonicalize paths, use allow-listed file identifiers instead of raw paths, enforce filesystem permissions, isolate application data, and monitor file access.

05 // SECURITY TOOL

Recommended security control

WAF + application file-access logging

Use non-sensitive lab files for testing.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.