Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is directory traversal?

Directory traversal manipulates a path so an application attempts to access files outside its intended directory. A traversal-looking request proves an attempt or test, not that protected content was disclosed.

Preserve each processing form

Retain the original path, encoding, gateway-decoded form, application interpretation, response code, size and body. Browsers, gateways and applications may normalise the same path differently; one representation may be blocked while another reaches the application.

Server-side file-access and application logs can show the actual target. A successful HTTP response can still be an error or generic page.

Define the disclosure scope

Where protected content was returned, preserve response headers and body and connect later use. One exposed file establishes that limited result, not wider filesystem access.

Establish the vulnerable condition and whether configuration, password, source, logs or keys were obtained. Separate the malicious request, processing, returned content and downstream compromise.

Key takeaway

Prove directory traversal by showing how the path was normalised and whether a specific protected file was returned, not from request syntax alone.

Reference: CIM-210Cyber Incidents & Offender Methods