Detailedlikelihood: Highseverity: MediumDraft

CAPEC-127Directory Indexing

Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
Medium

Description

An adversary crafts a request to a target that results in the target listing/indexing the content of a directory as output. One common method of triggering directory contents as output is to construct a request containing a path that terminates in a directory name rather than a file name since many applications are configured to provide a list of the directory's contents when such a request is received. An adversary can use this to explore the directory tree on a target as well as learn the names of files. This can often end up revealing test files, backup files, temporary files, hidden files, configuration files, user accounts, script contents, as well as naming conventions, all of which can be used by an attacker to mount additional attacks.

Related weaknesses· 7

CWE-424CWE-425CWE-288CWE-285CWE-732CWE-276CWE-693

MITRE ATT&CK crosswalk· 1

T1083: File and Directory Discovery

Related attack patterns· 1

CAPEC-54 (ChildOf)

Exploits7

TypeTargetConfidenceTier
WeaknessImproper Protection of Alternate Pathcwe-424100%live
WeaknessIncorrect Default Permissionscwe-276100%live
WeaknessDirect Request ('Forced Browsing')cwe-425100%live
WeaknessProtection Mechanism Failurecwe-693100%live
WeaknessImproper Authorizationcwe-285100%live
WeaknessAuthentication Bypass Using an Alternate Path or Channelcwe-288100%live
WeaknessIncorrect Permission Assignment for Critical Resourcecwe-732100%live

Related to1

TypeTargetConfidenceTier
TechniqueFile and Directory Discoveryt1083100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Identify Shared Files/Directories on System
CAPEC
DEPRECATED: Directory Traversal
CAPEC
Absolute Path Traversal
CAPEC
Path Traversal
CAPEC
File Discovery
CAPEC
Collect Data from Common Resource Locations
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.