Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

ByteMastermind/dotdotslash

Repository files navigation

dotdotslash

An tool to help you search for Directory Traversal Vulnerabilities

Benchmarks

Platforms that I tested to validate tool efficiency:

Screenshots

Screenshot

Screenshot

Screenshot

Instalation

You can download the last version cloning this repository

git clone https://github.com/jcesarstef/dotdotslash/

This tool was made to work with Python3

Usage

> python3 dotdotslash.py --help
usage: dotdotslash.py [-h] --url URL --string STRING [--cookie COOKIE] [--depth DEPTH] [--min-depth MIN_DEPTH] [--max-depth MAX_DEPTH] [--verbose] [--extension EXTENSION] [--lightweight]
dot dot slash - An automated Path Traversal Tester. Created by @jcesarstef, ByteMastermind's fork
options:
 -h, --help show this help message and exit
 --url URL, -u URL Url to attack.
 --string STRING, -s STRING
 String in --url to attack. Ex: document.pdf
 --cookie COOKIE, -c COOKIE
 Document cookie.
 --depth DEPTH, -d DEPTH
 How deep we will go? (backward compatibility, sets range 0 to depth)
 --min-depth MIN_DEPTH
 Minimum depth to test (use with --max-depth)
 --max-depth MAX_DEPTH
 Maximum depth to test (use with --min-depth)
 --verbose, -v Show requests
 --extension EXTENSION, -e EXTENSION
 File extension for null byte injection (e.g., ".png", ".txt"). Can be used multiple times.
 --lightweight, -l lightweight mode - group similar encodings instead of trying all combinations

Example:

python3 dotdotslash.py \
--url "http://192.168.58.101/bWAPP/directory_traversal_1.php?page=FUZZ" \
--string "a.txt" \
--cookie "PHPSESSID=089b49151627773d699c277c769d67cb; security_level=3" \
-e ".png" -e ".jpg" \
-v \
-l \
--min-depth 2 \
--max-depth 5

Let Me Know What You Think

About

Search for Directory Traversal Vulnerabilities

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

Contributors

Languages

  • Python 100.0%

AltStyle によって変換されたページ (->オリジナル) /