> For the complete documentation index, see [llms.txt](https://kunalwalavalkar.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kunalwalavalkar.gitbook.io/write-ups/portswigger-labs/server-side-topics/path-traversal/file-path-traversal-traversal-sequences-stripped-non-recursively.md).

# File path traversal, traversal sequences stripped non-recursively

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FI4ZXi5BKf4DYbAtrfLJC%2F1.png?alt=media&amp;token=493ae573-d417-490a-acbb-4ecbb0675e58" alt=""><figcaption></figcaption></figure>

Let's access the image through the browser.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FoTMI9FftrEd0nEXqV2l8%2F2.png?alt=media&amp;token=aa258ac4-6fca-4267-b214-3ecd02b9fd94" alt=""><figcaption></figcaption></figure>

We can intercept this request in [Burp Suite](https://portswigger.net/burp) using the `Proxy`.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FI6fytBn2kj2taPUYmp0A%2F3.png?alt=media&amp;token=f89668e5-512e-4a92-b893-ad634c615f95" alt=""><figcaption></figcaption></figure>

Now, we can sent this intercepted request to the `Repeater` to modify it.

Once in the `Repeater`, we can set the `filename` parameter to the following:

```
../../../etc/passwd
```

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FWpyuGDrssmUjznOnSnHl%2F4.png?alt=media&amp;token=810a707a-0f1d-43ec-8cf0-f23468909de7" alt=""><figcaption></figcaption></figure>

The server tells us that the file does not exist. This is because the `../` characters are being stripped from our parameter.

| Original            | Stripped   |
| ------------------- | ---------- |
| ../../../etc/passwd | etc/passwd |

The problem is, the server does not strip the parameters recursively,&#x20;

We can exploit it by setting the `filename` parameter to the following:

```
....//....//....//etc/passwd
```

Now, when the `../` characters are stripped it still leaves a set of `../` characters.

| Original                     | Stripped            |
| ---------------------------- | ------------------- |
| ....//....//....//etc/passwd | ../../../etc/passwd |

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FEKsc7asUwRRsnPrNvxuH%2F5.png?alt=media&amp;token=959124a9-9421-4313-b80a-5b970ad1a38e" alt=""><figcaption></figcaption></figure>

We have successfully solved the lab.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FzcB18ozxuJ58m5wq55Co%2F6.png?alt=media&amp;token=beb362da-2f2c-408a-b4a0-7a7f9c11d5f8" alt=""><figcaption></figcaption></figure>
