Skip to main content

path-traversal

Hunt directory traversal and archive traversal (ZipSlip/TarSlip) from user input to filesystem operations.

跳到安装

来源信息

仓库
BitterSecurity/Decepticon
最近来源活动
2026年6月2日 17:42
检测到的 SKILL.md 语言
英语
星标
5,565
分支
1,053

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
path-traversal
description
Hunt directory traversal and archive traversal (ZipSlip/TarSlip) from user input to filesystem operations.
metadata
{"subdomain":"web-exploitation","when_to_use":"path directory traversal zipslip tarslip archive filesystem cwe-22 dot dot slash"}
# Path Traversal Playbook ## Find sinks - `open(user_path)`, `send_file(user_path)`, file download endpoints, archive extraction APIs. ## Probe payload classes - Relative traversal: `../../../../etc/passwd` - Encoded traversal: `%2e%2e%2f` - Mixed separators: `..\\..\\windows\\win.ini` - Archive traversal: entries like `../../app/config.py` ## Verify controls - Canonicalization done before allowlist check. - Path confinement to intended root. ## Validation Confirm unauthorized file read/write outside allowed directory with positive and negative controls.
在 GitHub 查看