Decoded: Path Traversal - A Hacker's Perspective by Edward Henriquez episode artwork

EPISODE · Apr 10, 2025 · 15 MIN

Decoded: Path Traversal - A Hacker's Perspective by Edward Henriquez

from Decoded: The Cybersecurity Podcast · host Edward Henriquez

Edward Henriquez's podcast script for Decoded: The Cybersecurity Podcast explains the Path Traversal vulnerability from a hacker's perspective. This technique exploits weaknesses in web applications that allow users to specify file paths. By manipulating these paths with sequences like "../", attackers can navigate outside intended directories to access sensitive files such as configuration files, source code, and SSH keys. Henriquez also describes advanced methods to bypass common defenses, like double encoding and null byte injection. The script uses a real-world example of a GitHub Enterprise vulnerability to illustrate the impact and emphasizes that trusting user-supplied file paths is the root cause. Finally, it provides concrete defense strategies for developers, including input sanitization, path normalization, and restricting file access.Patreon Support:https://www.patreon.com/DecodedPodcast

Episode metadata supplied by the publisher feed · Published Apr 10, 2025

Embed this episode

NOW PLAYING

Decoded: Path Traversal - A Hacker's Perspective by Edward Henriquez

0:00 15:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Decoded: The Cybersecurity Podcast?

This episode is 15 minutes long.

When was this Decoded: The Cybersecurity Podcast episode published?

This episode was published on April 10, 2025.

Can I download this Decoded: The Cybersecurity Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!