performing-directory-traversal-testing
Installation
SKILL.md
Performing Directory Traversal Testing
When to Use
- During authorized penetration tests when the application handles file paths in URL parameters or request bodies
- When testing file download, file view, or file include functionality
- For assessing Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerabilities
- When evaluating template engines, logging systems, or report generators that reference files
- During security assessments of APIs that accept file names or paths as parameters
Prerequisites
- Authorization: Written penetration testing agreement for the target
- Burp Suite Professional: For intercepting and modifying file path parameters
- ffuf: For fuzzing file path parameters with traversal payloads
- dotdotpwn: Automated directory traversal fuzzer (
apt install dotdotpwn) - SecLists: Traversal payload wordlists from Daniel Miessler's collection
- curl: For manual testing of traversal payloads