Path Traversal Testing

当对授权目标做 Web 渗透、需检测/利用文件路径遍历(目录遍历/LFI)以读取服务器任意文件时使用;做参数定位、payload 构造与绕过、敏感文件读取乃至 LFI 提权到 RCE 的实操并产出漏洞证据与修复建议;不适用于未授权测试或生产数据破坏。触发词:路径遍历、目录遍历、LFI、../etc/passwd、文件下载参数

findscripter 39d2418 8.0 KB Updated

File contents

findscripter/everything-skills/tree/main/08-security/path-traversal-testing commit 39d2418271

Frequently asked questions

npx skillmds@latest add findscripter/path-traversal-testing