Path Traversal Exploitation Attempts

 Original Source: [Sigma source]
Title: Path Traversal Exploitation Attempts
Status: test
Description:Detects path traversal exploitation attempts
References:
  -https://github.com/projectdiscovery/nuclei-templates
  -https://book.hacktricks.xyz/pentesting-web/file-inclusion
Author: Subhash Popuri (@pbssubhash), Florian Roth (Nextron Systems), Thurein Oo, Nasreddine Bencherchali (Nextron Systems)
Date: 2021-09-25
modified:2023-08-31
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
Logsource:
  • category: webserver
Detection:
  selection:
    cs-uri-query|contains:
      -'../../../../../lib/password'
      -'../../../../windows/'
      -'../../../etc/'
      -'..%252f..%252f..%252fetc%252f'
      -'..%c0%af..%c0%af..%c0%afetc%c0%af'
      -'%252e%252e%252fetc%252f'

  condition:selection
Falsepositives:
  -Expected to be continuously seen on systems exposed to the Internet
  -Internal vulnerability scanners
Level: medium