Decoded: The Cybersecurity Podcast

Decoded: Path Traversal - A Hacker's Perspective by Edward Henriquez


Listen Later

Edward Henriquez's podcast script for Decoded: The Cybersecurity Podcast explains the Path Traversal vulnerability from a hacker's perspective. This technique exploits weaknesses in web applications that allow users to specify file paths. By manipulating these paths with sequences like "../", attackers can navigate outside intended directories to access sensitive files such as configuration files, source code, and SSH keys. Henriquez also describes advanced methods to bypass common defenses, like double encoding and null byte injection. The script uses a real-world example of a GitHub Enterprise vulnerability to illustrate the impact and emphasizes that trusting user-supplied file paths is the root cause. Finally, it provides concrete defense strategies for developers, including input sanitization, path normalization, and restricting file access.


Patreon Support:


https://www.patreon.com/DecodedPodcast

...more
View all episodesView all episodes
Download on the App Store

Decoded: The Cybersecurity PodcastBy Edward Henriquez

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

4 ratings


More shows like Decoded: The Cybersecurity Podcast

View all
Tech News Weekly (Audio) by TWiT

Tech News Weekly (Audio)

1,072 Listeners

The EDM Prodcast by EDMProd

The EDM Prodcast

163 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,018 Listeners

Professor Messer's Security+ Study Group by Professor Messer

Professor Messer's Security+ Study Group

137 Listeners

Click Here by Recorded Future News

Click Here

405 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,951 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

129 Listeners

Artificial Intelligence: AI News, ChatGPT, OpenAI, LLM, Anthropic, Claude, Google AI by Eli Schafer

Artificial Intelligence: AI News, ChatGPT, OpenAI, LLM, Anthropic, Claude, Google AI

13 Listeners

CISSP Cyber Training Podcast - CISSP Training Program by Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur

CISSP Cyber Training Podcast - CISSP Training Program

30 Listeners

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

513 Listeners

Using AI at Work: AI in the Workplace & Generative AI for Business Leaders by Chris Daigle

Using AI at Work: AI in the Workplace & Generative AI for Business Leaders

18 Listeners

CISSP Central by Krishnakumar Mahadevan

CISSP Central

0 Listeners