File path traversal, validation of start of path

7 hours ago 10
BOOK THIS SPACE FOR AD
ARTICLE AD

Laxious

First of all open up the Foxy proxy or chromium. And go to the HTTP history and you should see something like this and image file with it too. You can choose any file what you want and right click it and send it to the repeater. In the request you will see something else than other labs. You will see the directories too i.e /var/www/image/.

As this lab says in the description it asks for the validation at the start and we can’t just add ../../../etc/passwd and as the directories are already mentioned in the request. we don’t have to add any more directories. Now just add the payload ../../../etc/passwd. In this lab, we don’t have to encode anything.

So this is the response that we get and the lab is solved..

And Your lab is solved………

Read Entire Article