Performing Directory Traversal Testing
When to Use
- During authorized penetration tests when the application handles file paths in URL parameters or request bodies
- When testing file download, file view, or file include functionality
- For assessing Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerabilities
- When evaluating template engines, logging systems, or report generators that reference files
- During security assessments of APIs that accept file names or paths as parameters
Prerequisites
- Authorization: Written penetration testing agreement for the target
- Burp Suite Professional: For intercepting and modifying file path parameters
- ffuf: For fuzzing file path parameters with traversal payloads
- dotdotpwn: Automated directory traversal fuzzer (
apt install dotdotpwn) - SecLists: Traversal payload wordlists from Daniel Miessler's collection
- curl: For manual testing of traversal payloads
Workflow
Step 1: Identify File Path Parameters
Find application endpoints that reference files through parameters.
# Common file-handling patterns to look for:
# /download?file=report.pdf
# /view?page=about.html
…