# Directory traversal and file access checklist

Understand how a path is constructed and normalized, then escape the intended directory to read application, operating-system, or authentication material.

## Recognition

- [ ] Parameters resemble file, page, template, language, theme, download, document, image, path, or directory names.
- [ ] Changing a value produces file-not-found, absolute-path, include, or directory-listing errors.
- [ ] A route returns server files or accepts a filename independent of an object authorization check.

## Manual workflow

- [ ] Determine the expected base directory, filename, extension, prefix, suffix, and whether the application accepts absolute paths.
- [ ] Test a known application file before distant operating-system paths so success is measurable.
- [ ] Increase traversal depth methodically and test Unix/Windows separators appropriate to the target.
- [ ] Evaluate URL encoding, double encoding, mixed separators, normalized dot segments, and validated-versus-used path differences.
- [ ] Test whether an enforced suffix can be bypassed or whether the desired file already matches it.
- [ ] Use controlled path wordlists only after learning the path grammar.
- [ ] Read configuration or source material that advances authentication, command execution, or the requested proof.

## Escalation

- [ ] Application source reveals hidden routes, secrets, database access, templates, and command construction.
- [ ] Configuration and environment files may provide administrator credentials or internal service locations.
- [ ] Log or file inclusion may become code execution only when the application actually interprets the included content.

## Pitfalls

- [ ] Using a fixed traversal depth without learning the working directory.
- [ ] Ignoring URL decoding performed by a proxy, framework, or front-end before application validation.
- [ ] Confusing an application-level download authorization issue with filesystem traversal.
- [ ] Claiming file access from an error without retrieving controlled or known content.

## Evidence

- [ ] Baseline file request
- [ ] Working traversal grammar
- [ ] Known file contents
- [ ] Sensitive file that advances the chain
- [ ] Resulting administrator or server proof

## Tools

- [ ] Burp/ZAP resend and decoder
- [ ] Wfuzz path fuzzing
- [ ] curl --path-as-is
- [ ] SecLists traversal lists used selectively

## Online references

- [PortSwigger traversal labs](<https://portswigger.net/web-security/file-path-traversal>)
- [OWASP traversal testing](<https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/11.1-Testing_for_File_Inclusion>)

> Do you want to live curiously?
