An analyst observes the following log entry on a web server: GET /../../etc/passwd HTTP/1.1 200. Which type of attack is indicated?
Trap 1: SSRF
Server-Side Request Forgery (SSRF) occurs when a web application is tricked into making requests to an arbitrary domain specified by the attacker, often targeting internal systems or other external services. The observed log entry, which shows an attempt to access a local file path using '../', does not involve the server initiating an outbound network request to another server or internal service. Instead, it's a direct manipulation of a local file path within the server's own file system, fundamentally different from an SSRF attack.
Trap 2: LFI
Local File Inclusion (LFI) vulnerabilities allow an attacker to include a file from the local server into the web application's response, often by manipulating a parameter that specifies a file path to be processed by a script. While LFI can sometimes utilize directory traversal sequences ('../'), the primary characteristic is the *inclusion* of the file's content into the rendered page or script execution context. The log entry, by contrast, indicates a direct attempt to *access* a file path, not necessarily to include its content within a server-side script's execution flow, making it a direct path traversal attempt.
Trap 3: Command injection
Command injection vulnerabilities allow an attacker to execute arbitrary operating system commands on the host server by injecting them into input fields that are subsequently passed to a system shell. This attack aims to run commands like 'ls', 'cat', or 'whoami'. The log entry, however, shows an attempt to manipulate a file path using '../' to access a specific file, which is a file system navigation operation, not the execution of an arbitrary OS command. Therefore, it does not align with the characteristics of command injection.
- A
Directory traversal
Directory traversal, also known as path traversal, is an attack that exploits vulnerabilities in web server software or applications to access files and directories stored outside the intended web root directory. The '../' sequence observed in the log entry is a classic technique used to navigate up the directory hierarchy, allowing an attacker to read sensitive files like configuration files, password files, or source code that should not be publicly accessible. This specific request clearly demonstrates an attempt to traverse directories to access '/etc/passwd'.
- B
SSRF
Why it fails: Server-Side Request Forgery (SSRF) occurs when a web application is tricked into making requests to an arbitrary domain specified by the attacker, often targeting internal systems or other external services. The observed log entry, which shows an attempt to access a local file path using '../', does not involve the server initiating an outbound network request to another server or internal service. Instead, it's a direct manipulation of a local file path within the server's own file system, fundamentally different from an SSRF attack.
- C
LFI
Why it fails: Local File Inclusion (LFI) vulnerabilities allow an attacker to include a file from the local server into the web application's response, often by manipulating a parameter that specifies a file path to be processed by a script. While LFI can sometimes utilize directory traversal sequences ('../'), the primary characteristic is the *inclusion* of the file's content into the rendered page or script execution context. The log entry, by contrast, indicates a direct attempt to *access* a file path, not necessarily to include its content within a server-side script's execution flow, making it a direct path traversal attempt.
- D
Command injection
Why it fails: Command injection vulnerabilities allow an attacker to execute arbitrary operating system commands on the host server by injecting them into input fields that are subsequently passed to a system shell. This attack aims to run commands like 'ls', 'cat', or 'whoami'. The log entry, however, shows an attempt to manipulate a file path using '../' to access a specific file, which is a file system navigation operation, not the execution of an arbitrary OS command. Therefore, it does not align with the characteristics of command injection.