-include-..-2f..-2f..-2f..-2froot-2f !!link!! ✦ Free & Complete
parameter in your example—an attacker can chain them together. For instance, ../../../../root/
: This is URL-encoded representation of the forward slash / . In a URL, %2F is used to represent a / to avoid confusion with the actual path separators. -include-..-2F..-2F..-2F..-2Froot-2F
Example ModSecurity rule snippet:
What or framework your application is built on? parameter in your example—an attacker can chain them
). Attackers often use encoding to bypass basic security filters that only look for literal characters. -include-..-2F..-2F..-2F..-2Froot-2F