Path Normalization Crash Course 101

zoid
10 min readApr 10, 2023
path-normalization crash-course-101

In this crash course, I will be teaching you the methods I use to find path normalization vulnerabilities. I will be discussing why you should invest time in this bug class, and the tools to use, here is what will be on the agenda.

Prerequisites

In order to understand this course, It’s required you have some basic understanding:

  • Of programming languages
  • Reverse proxies
  • Understanding of HTTP
  • You will also need to be able to perform recon on your targets with open-source tools or your own.

Enjoy, I hope you learn a thing or two.

Why should you choose this bug class?

Firstly, we're dealing with internal services that backend engineers have developed, so, from a hacker's perspective these are perfect targets if the threat actor's intention is to gain unauthorized access to Personal Identifiable Information (PII)…

--

--

zoid

Content Engineer at @pentesterlab freelance pentester for Cobalt & Synack.