Basically, if you add a ../ in a query, you can start to work backwards in the directory tree to root, then go up again to someplace you shouldn't go. The firewall doesn't block this attack, cause it's just doing a regular HTTP(s) request.
How would a firewall be related to this? A firewall would block/allow the ports 80/443 from certain sources. That’s it. Whatever is happening here it’s related to OS permissions and web server configuration.
5 replies
It's called a Path Traversal attack.
Basically, if you add a ../ in a query, you can start to work backwards in the directory tree to root, then go up again to someplace you shouldn't go. The firewall doesn't block this attack, cause it's just doing a regular HTTP(s) request.
https://owasp.org/www-community/attacks/Path_Traversal
How would a firewall be related to this? A firewall would block/allow the ports 80/443 from certain sources. That’s it. Whatever is happening here it’s related to OS permissions and web server configuration.
It's referring to a Web Application Firewall.
MOOPSY!!!
That's all you need to know ...
I JUST watched that episode! Pretty nuts to see moopsy here.
Like ten minutes ago just!