During a forensic investigation of a compromised web server, an analyst finds the following entry in the IIS access log: 192.168.1.5, -, 04/May/2024:14:23:11, GET /scripts/..%5c../windows/system32/cmd.exe, 200. What is the probable attack vector?
The ..%5c.. sequence is URL encoding where %5c represents a backslash, so the payload decodes to ..\.., the classic directory-traversal prefix used to escape the web root. When processed by a vulnerable IIS server, this allowed an attacker to request files like C:\windows\system32\cmd.exe with the unencoded traversal string intact. The request is a single crafted path with encoded separators, which is precisely the signature of a path traversal attack rather than any of the other categories listed.
Why this answer
The log shows a path traversal attempt using URL-encoded backslashes (%5c) to navigate to cmd.exe. The 200 status indicates the request succeeded. This is a classic path traversal attack.