Section 1 of 5
Introduction
Web applications constantly work with files. They serve images, load templates, generate reports, read configuration, and process user-supplied documents. Every one of these operations involves a filesystem path: a structured reference to a specific location on the server.
When an application allows user input to influence which file or resource is accessed, a security boundary is created. If that boundary is not enforced correctly, an attacker may be able to reach files and resources that were never intended to be accessible. This module examines three related but distinct vulnerability classes that arise from this boundary:
- Path Traversal, where an attacker manipulates a path so the application resolves an unintended filesystem location.
- Local File Inclusion (LFI), where an attacker influences the selection of a local resource that the application then includes or processes.
- Remote File Inclusion (RFI), where an attacker influences the application to include or process a resource hosted on a remote system.
In this module, you will learn:
- How filesystem paths work and how applications use them.
- What Path Traversal is, how it occurs, and how it is tested.
- How filtering, encoding, and normalization affect path handling.
- What LFI is and how it differs from simple file reading.
- What RFI is and why it is less common today.
- How Path Traversal, LFI, and RFI relate to one another without being identical.
- How to assess impact and recommend mitigation.
- How to perform a complete authorized testing workflow.
Why This Matters
Path and inclusion vulnerabilities are dangerous because they cross a trust boundary between application input and filesystem resources. A weakness can lead to sensitive file disclosure, exposure of configuration or credentials, unauthorized resource processing, and, in specific configurations, code execution. Understanding the distinctions between these vulnerability classes is essential for accurate testing and reporting.