{"id":476846,"date":"2023-08-09T09:04:34","date_gmt":"2023-08-09T09:04:34","guid":{"rendered":""},"modified":"2023-09-05T11:13:34","modified_gmt":"2023-09-05T11:13:34","slug":"directory-traversal-attack","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/tr\/wiki\/directory-traversal-attack\/","title":{"rendered":"Dizin ge\u00e7i\u015f sald\u0131r\u0131s\u0131"},"content":{"rendered":"<p>Yol ge\u00e7i\u015f sald\u0131r\u0131lar\u0131 olarak da bilinen dizin ge\u00e7i\u015f sald\u0131r\u0131lar\u0131, web g\u00fcvenli\u011fi alan\u0131nda \u00f6nemli bir risk olu\u015fturur. \u00d6ncelikle bir web uygulamas\u0131n\u0131n sunucuda bulunan dosyalara eri\u015fme i\u015flevindeki g\u00fcvenlik a\u00e7\u0131\u011f\u0131ndan yararlan\u0131rlar. Bu sald\u0131r\u0131lar, k\u00f6t\u00fc niyetli bir kullan\u0131c\u0131n\u0131n, &quot;nokta-nokta-e\u011fik \u00e7izgi (..\/)&quot; dizileriyle dosyalara referans veren de\u011fi\u015fkenleri manip\u00fcle ederek, web k\u00f6k\u00fc klas\u00f6r\u00fc d\u0131\u015f\u0131nda depolanan dosyalara ve dizinlere eri\u015fmesine olanak tan\u0131r.<\/p>\n<h2>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131n\u0131n Geli\u015fimi<\/h2>\n<p>Dizin ge\u00e7i\u015f sald\u0131r\u0131lar\u0131n\u0131n k\u00f6keni, web uygulamalar\u0131n\u0131n sunucu taraf\u0131ndaki dosyalara eri\u015fmek i\u00e7in komut dosyalar\u0131n\u0131 ilk kez kullanmaya ba\u015flad\u0131\u011f\u0131 internetin ilk g\u00fcnlerine kadar izlenebilir. Teknoloji ilerledik\u00e7e ve web uygulamalar\u0131 karma\u015f\u0131kla\u015ft\u0131k\u00e7a bu t\u00fcr g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131n potansiyeli de artt\u0131.<\/p>\n<p>Bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131n\u0131n temel yap\u0131s\u0131ndan dolay\u0131, dizin ge\u00e7i\u015f sald\u0131r\u0131lar\u0131ndan ilk kez bahsedildi\u011finin kesin olarak belirlenmesi biraz zordur. Ancak, 1990&#039;lar\u0131n sonlar\u0131nda ve 2000&#039;lerin ba\u015flar\u0131nda, web uygulamalar\u0131 yayg\u0131nla\u015ft\u0131k\u00e7a ve g\u00fcvenli olmayan dosya referanslar\u0131ndan yararlanma f\u0131rsatlar\u0131 artt\u0131k\u00e7a, g\u00fcvenlik kayg\u0131s\u0131 daha da belirgin hale geldi.<\/p>\n<h2>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131n\u0131 Geni\u015fletmek<\/h2>\n<p>Dizin ge\u00e7i\u015f sald\u0131r\u0131s\u0131, bir bilgisayar korsan\u0131n\u0131n genellikle halka a\u00e7\u0131k olmayan bir sunucunun dizinine eri\u015fti\u011fi bir HTTP istismar bi\u00e7imidir. Sald\u0131rgan, kullan\u0131c\u0131 taraf\u0131ndan sa\u011flanan giri\u015f dosyas\u0131 adlar\u0131n\u0131n yetersiz g\u00fcvenlik do\u011frulamas\u0131ndan veya ar\u0131nd\u0131r\u0131lmas\u0131ndan yararlan\u0131r ve b\u00f6ylece k\u0131s\u0131tl\u0131 ortamdan \u00e7\u0131kmalar\u0131na olanak tan\u0131r.<\/p>\n<p>Dizin ge\u00e7i\u015f dizilerinin en yayg\u0131n kullan\u0131m\u0131 URL tabanl\u0131 sald\u0131r\u0131lardad\u0131r, ancak bunlar ayn\u0131 zamanda ba\u015fl\u0131k enjeksiyonlar\u0131nda, \u00e7erez manip\u00fclasyonlar\u0131nda ve hatta POST parametrelerinde de g\u00f6r\u00fcnebilir. Bu sayede sald\u0131rganlar, k\u0131s\u0131tlanm\u0131\u015f dizinleri g\u00f6r\u00fcnt\u00fcleyebilir ve web sunucusunun k\u00f6k dizini d\u0131\u015f\u0131ndaki komutlar\u0131 \u00e7al\u0131\u015ft\u0131rabilir, b\u00f6ylece hassas bilgilere yetkisiz eri\u015fim elde edebilir.<\/p>\n<h2>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131 Nas\u0131l \u00c7al\u0131\u015f\u0131r?<\/h2>\n<p>Dizin ge\u00e7i\u015f sald\u0131r\u0131s\u0131, kullan\u0131c\u0131 taraf\u0131ndan sa\u011flanan giri\u015f dosya adlar\u0131n\u0131n yetersiz g\u00fcvenlik do\u011frulamas\u0131ndan\/temizlenmesinden yararlanarak \u00e7al\u0131\u015f\u0131r, b\u00f6ylece bir sald\u0131rgan, k\u0131s\u0131tl\u0131 konumun d\u0131\u015f\u0131na atlamak i\u00e7in bunlar\u0131 manip\u00fcle edebilir.<\/p>\n<p>A\u015f\u0131r\u0131 basitle\u015ftirilmi\u015f bir bi\u00e7imde, bir uygulaman\u0131n sunucudaki bir g\u00f6r\u00fcnt\u00fc dosyas\u0131na eri\u015fmeye \u00e7al\u0131\u015ft\u0131\u011f\u0131 bir senaryoyu ele alal\u0131m:<\/p>\n<pre><div class=\"bg-black rounded-md mb-4\"><div class=\"flex items-center relative text-gray-200 bg-gray-800 px-4 py-2 text-xs font-sans justify-between rounded-t-md\"><span>arduino<\/span><button class=\"flex ml-auto gap-2\"><svg stroke=\"currentColor\" fill=\"none\" stroke-width=\"2\" viewbox=\"0 0 24 24\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-4 w-4\" height=\"1em\" width=\"1em\" ><path d=\"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2\"><\/path><rect x=\"8\" y=\"2\" width=\"8\" height=\"4\" rx=\"1\" ry=\"1\"><\/rect><\/svg>Kodu kopyala<\/button><\/div><div class=\"p-4 overflow-y-auto\"><code class=\"!whitespace-pre hljs language-arduino\" data-no-translation=\"\">http:<span class=\"hljs-comment\">\/\/example.com\/app?file=logo.jpg<\/span>\n<\/code><\/div><\/div><\/pre>\n<p>Bu durumda uygulama dosyay\u0131 a\u00e7acakt\u0131r. <code data-no-translation=\"\">logo.jpg<\/code> resimler dizininden. Ancak bir sald\u0131rgan, ana dizine \u00e7\u0131kmak i\u00e7in &quot;nokta-nokta-e\u011fik \u00e7izgi (..\/)&quot; dizilerini kullanabilir ve ard\u0131ndan yetkisiz dosyalara eri\u015febilir. \u00d6rne\u011fin:<\/p>\n<pre><div class=\"bg-black rounded-md mb-4\"><div class=\"flex items-center relative text-gray-200 bg-gray-800 px-4 py-2 text-xs font-sans justify-between rounded-t-md\"><span>darbe<\/span><button class=\"flex ml-auto gap-2\"><svg stroke=\"currentColor\" fill=\"none\" stroke-width=\"2\" viewbox=\"0 0 24 24\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"h-4 w-4\" height=\"1em\" width=\"1em\" ><path d=\"M16 4h2a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H6a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2h2\"><\/path><rect x=\"8\" y=\"2\" width=\"8\" height=\"4\" rx=\"1\" ry=\"1\"><\/rect><\/svg>Kodu kopyala<\/button><\/div><div class=\"p-4 overflow-y-auto\"><code class=\"!whitespace-pre hljs language-bash\" data-no-translation=\"\">http:\/\/example.com\/app?file=..\/..\/etc\/passwd\n<\/code><\/div><\/div><\/pre>\n<p>Bu, uygulaman\u0131n hassas sistem dosyalar\u0131n\u0131 g\u00f6r\u00fcnt\u00fclemesine neden olabilir.<\/p>\n<h2>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131n\u0131n Temel \u00d6zellikleri<\/h2>\n<ol>\n<li>\n<p><strong>De\u011fi\u015fkenleri Manip\u00fcle Etme:<\/strong> Dizin ge\u00e7i\u015f sald\u0131r\u0131s\u0131n\u0131n temel \u00f6zelli\u011fi, dosyalara &quot;nokta-nokta-e\u011fik \u00e7izgi (..\/)&quot; dizileriyle ba\u015fvuran de\u011fi\u015fkenlerin manip\u00fcle edilmesini i\u00e7erir.<\/p>\n<\/li>\n<li>\n<p><strong>K\u0131s\u0131tlamalar\u0131 A\u015fmak:<\/strong> Sald\u0131rgan\u0131n uygulaman\u0131n k\u00f6k dizininden \u00e7\u0131k\u0131p dosya sisteminin di\u011fer b\u00f6l\u00fcmlerine eri\u015fmesini sa\u011flar.<\/p>\n<\/li>\n<li>\n<p><strong>Zay\u0131f Do\u011frulamadan Yararlanma:<\/strong> Dizin ge\u00e7i\u015f sald\u0131r\u0131lar\u0131, kullan\u0131c\u0131 giri\u015flerinin zay\u0131f do\u011frulamas\u0131ndan veya ar\u0131nd\u0131r\u0131lmas\u0131ndan yararlan\u0131r.<\/p>\n<\/li>\n<\/ol>\n<h2>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131n\u0131n T\u00fcrleri<\/h2>\n<p>Dizin ge\u00e7i\u015f sald\u0131r\u0131lar\u0131n\u0131n ard\u0131ndaki temel prensip ayn\u0131 kalsa da, s\u00f6z konusu ba\u011flama ve uygulamaya ba\u011fl\u0131 olarak farkl\u0131 \u015fekillerde ortaya \u00e7\u0131kabilirler:<\/p>\n<ol>\n<li>\n<p><strong>URL Tabanl\u0131 Sald\u0131r\u0131lar:<\/strong> Bunlar, dizinler aras\u0131nda ge\u00e7i\u015f yapmak i\u00e7in URL&#039;ye k\u00f6t\u00fc ama\u00e7l\u0131 girdi enjekte etmeyi i\u00e7erir.<\/p>\n<\/li>\n<li>\n<p><strong>Form Tabanl\u0131 Sald\u0131r\u0131lar:<\/strong> Savunmas\u0131z sunucu taraf\u0131 komut dosyalar\u0131ndan yararlanmak i\u00e7in form alanlar\u0131na k\u00f6t\u00fc ama\u00e7l\u0131 girdiler eklenir.<\/p>\n<\/li>\n<li>\n<p><strong>\u00c7erez Tabanl\u0131 Sald\u0131r\u0131lar:<\/strong> Sald\u0131rganlar, dizinler aras\u0131nda ge\u00e7i\u015f yapmak ve yetkisiz verilere eri\u015fmek i\u00e7in \u00e7erezleri kullan\u0131r.<\/p>\n<\/li>\n<\/ol>\n<table>\n<thead>\n<tr>\n<th>Tip<\/th>\n<th>Tan\u0131m<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>URL Tabanl\u0131 Sald\u0131r\u0131lar<\/td>\n<td>Dizinler aras\u0131nda ge\u00e7i\u015f yapmak i\u00e7in URL&#039;ye k\u00f6t\u00fc ama\u00e7l\u0131 girdi enjekte edin.<\/td>\n<\/tr>\n<tr>\n<td>Form Tabanl\u0131 Sald\u0131r\u0131lar<\/td>\n<td>Sunucu taraf\u0131 komut dosyalar\u0131ndan yararlanmak i\u00e7in form alanlar\u0131na k\u00f6t\u00fc ama\u00e7l\u0131 girdiler ekleyin.<\/td>\n<\/tr>\n<tr>\n<td>\u00c7erez Tabanl\u0131 Sald\u0131r\u0131lar<\/td>\n<td>Dizinler aras\u0131nda ge\u00e7i\u015f yapmak ve yetkisiz verilere eri\u015fmek i\u00e7in \u00e7erezleri y\u00f6netin.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131yla \u0130li\u015fkili Sorunlar ve \u00c7\u00f6z\u00fcmler<\/h2>\n<p>Dizin ge\u00e7i\u015f sald\u0131r\u0131lar\u0131yla ilgili temel sorun, hassas dosyalara ve verilere yetkisiz eri\u015fimdir. Bu, veri s\u0131z\u0131nt\u0131s\u0131na, gizlilik kayb\u0131na ve potansiyel olarak sald\u0131rgana ba\u015fka sald\u0131r\u0131 vekt\u00f6rleri sa\u011flanmas\u0131na (yap\u0131land\u0131rma dosyalar\u0131ndan veritaban\u0131 kimlik bilgilerinin al\u0131nmas\u0131 gibi) yol a\u00e7abilir.<\/p>\n<p>\u0130\u015fte baz\u0131 \u00e7\u00f6z\u00fcmler:<\/p>\n<ol>\n<li>\n<p><strong>Giri\u015f Do\u011frulamas\u0131:<\/strong> Kullan\u0131c\u0131 taraf\u0131ndan sa\u011flanan giri\u015flerin sa\u011flam bir \u015fekilde do\u011frulanmas\u0131n\u0131 sa\u011flay\u0131n. Giri\u015flerin bir par\u00e7as\u0131 olarak \u201c..\u201d veya \u201c\/\u201d karakterlerine izin vermeyin.<\/p>\n<\/li>\n<li>\n<p><strong>Giri\u015f kontrolu:<\/strong> Uygun eri\u015fim kontrol\u00fcn\u00fc uygulay\u0131n. Kullan\u0131c\u0131ya yetki vermek i\u00e7in yaln\u0131zca sa\u011flanan dosya yoluna g\u00fcvenmeyin.<\/p>\n<\/li>\n<li>\n<p><strong>En Az Ayr\u0131cal\u0131k \u0130lkesi:<\/strong> Uygulamay\u0131 gereken en az ayr\u0131cal\u0131kla \u00e7al\u0131\u015ft\u0131rarak dizin ge\u00e7i\u015fi sald\u0131r\u0131s\u0131ndan kaynaklanabilecek olas\u0131 hasar\u0131 azalt\u0131n.<\/p>\n<\/li>\n<\/ol>\n<h2>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131 ve Benzer Terimler<\/h2>\n<table>\n<thead>\n<tr>\n<th>Terim<\/th>\n<th>Tan\u0131m<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131s\u0131<\/td>\n<td>Yetkisiz dosyalara ve dizinlere eri\u015fmek i\u00e7in kullan\u0131c\u0131 giri\u015f prosed\u00fcrlerindeki bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131ndan yararlan\u0131r.<\/td>\n<\/tr>\n<tr>\n<td>Uzaktan Dosya Ekleme (RFI)<\/td>\n<td>Sald\u0131rgan, k\u00f6t\u00fc ama\u00e7l\u0131 bir komut dosyas\u0131n\u0131 bir web sitesinin sunucusuna y\u00fcklemek i\u00e7in kullan\u0131c\u0131 giri\u015f yollar\u0131n\u0131 kullan\u0131r.<\/td>\n<\/tr>\n<tr>\n<td>Yerel Dosya Ekleme (LFI)<\/td>\n<td>Sald\u0131rgan, bir web sitesini, web sunucusundaki dosyalar\u0131n i\u00e7eri\u011fini \u00e7al\u0131\u015ft\u0131racak veya a\u00e7\u0131\u011fa \u00e7\u0131karacak \u015fekilde y\u00f6nlendirir.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131yla \u0130lgili Gelecek Perspektifleri ve Teknolojiler<\/h2>\n<p>Web geli\u015ftirme ortam\u0131 geli\u015ftik\u00e7e, dizin ge\u00e7i\u015f sald\u0131r\u0131lar\u0131n\u0131 ger\u00e7ekle\u015ftirme y\u00f6ntemleri ve ara\u00e7lar\u0131 daha karma\u015f\u0131k hale gelebilir. Bununla birlikte, \u00f6nlemenin temeli muhtemelen h\u00e2l\u00e2 sa\u011flam girdi do\u011frulama ve mant\u0131kl\u0131 sistem yap\u0131land\u0131rmas\u0131nda yatacakt\u0131r.<\/p>\n<p>\u0130zinsiz giri\u015f tespit sistemleri i\u00e7in web uygulamas\u0131 g\u00fcvenlik duvarlar\u0131, anormallik tespit sistemleri ve makine \u00f6\u011frenimi algoritmalar\u0131, bu t\u00fcr sald\u0131r\u0131lara kar\u015f\u0131 gelecekteki azaltma stratejilerinde \u00f6nemli bir rol oynayabilir.<\/p>\n<h2>Proxy Sunucular Aras\u0131ndaki Ba\u011flant\u0131 ve Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131<\/h2>\n<p>Proxy sunucular\u0131, dizin ge\u00e7i\u015fi sald\u0131r\u0131lar\u0131na kar\u015f\u0131 ek bir g\u00fcvenlik katman\u0131 g\u00f6revi g\u00f6rebilir. \u0130stemci ile sunucu aras\u0131ndaki istekleri ve yan\u0131tlar\u0131 filtreleyerek, ola\u011fand\u0131\u015f\u0131 kal\u0131plar\u0131n veya dizin ge\u00e7i\u015f sald\u0131r\u0131lar\u0131n\u0131n i\u015faretlerinin tespit edilmesine yard\u0131mc\u0131 olabilirler ve b\u00f6ylece bunlar\u0131n sunucuya ula\u015fmas\u0131n\u0131 engelleyebilirler.<\/p>\n<p>\u00d6rne\u011fin OneProxy, bu t\u00fcr sald\u0131r\u0131lara kar\u015f\u0131 savunma stratejinizde \u00f6nemli bir rol oynayabilecek sa\u011flam bir proxy sunucu \u00e7\u00f6z\u00fcm\u00fc sa\u011flar.<\/p>\n<h2>\u0130lgili Ba\u011flant\u0131lar<\/h2>\n<ol>\n<li><a href=\"https:\/\/owasp.org\/www-community\/attacks\/Path_Traversal\" target=\"_new\" rel=\"noopener nofollow\">OWASP Yol Ge\u00e7i\u015fi Sald\u0131r\u0131s\u0131<\/a><\/li>\n<li><a href=\"https:\/\/www.acunetix.com\/blog\/articles\/directory-traversal\/\" target=\"_new\" rel=\"noopener nofollow\">Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131 ve Etki Azaltma Teknikleri<\/a><\/li>\n<li><a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/File_Path_Traversal_Prevention_Cheat_Sheet.html\" target=\"_new\" rel=\"noopener nofollow\">Dizin Ge\u00e7i\u015fi Sald\u0131r\u0131lar\u0131n\u0131 \u00d6nleme<\/a><\/li>\n<li><a href=\"https:\/\/www.owasp.org\/index.php\/Guide_to_Building_Secure_Web_Applications_and_Web_Services\" target=\"_new\" rel=\"noopener nofollow\">OWASP G\u00fcvenli Web Uygulamalar\u0131 ve Web Hizmetleri Olu\u015fturma K\u0131lavuzu<\/a><\/li>\n<li><a href=\"https:\/\/www.cloudflare.com\/en-gb\/learning\/security\/glossary\/what-is-a-proxy-server\/\" target=\"_new\" rel=\"noopener nofollow\">Proxy Sunucular\u0131 ve G\u00fcvenlik<\/a><\/li>\n<\/ol>","protected":false},"featured_media":476847,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-476846","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Directory Traversal Attack: An In-Depth Examination<\/mark>","faq_items":[{"question":"What is a Directory Traversal Attack?","answer":"<p>A Directory Traversal Attack, also known as a path traversal attack, is a type of HTTP exploit that allows attackers to access restricted directories and execute commands outside of the web server's root directory. This is accomplished by exploiting insufficient security validation or sanitization of user-supplied input filenames.<\/p>"},{"question":"How did Directory Traversal Attacks originate?","answer":"<p>Directory Traversal Attacks originated during the early days of the internet when web applications began utilizing scripts to access server-side files. As technology progressed and web applications became more complex, the potential for these types of vulnerabilities also increased.<\/p>"},{"question":"How does a Directory Traversal Attack work?","answer":"<p>Directory Traversal Attacks work by manipulating variables that reference files with \"dot-dot-slash (..\/)\" sequences. By exploiting weak security validation or sanitization of user inputs, an attacker can access files and directories outside the webroot folder.<\/p>"},{"question":"What are the key features of Directory Traversal Attacks?","answer":"<p>Key features of Directory Traversal Attacks include the manipulation of variables to traverse directories, the ability to break out of the application's root directory, and the exploitation of weak validation of user inputs.<\/p>"},{"question":"What are the different types of Directory Traversal Attacks?","answer":"<p>Directory Traversal Attacks can be categorized into URL-based, form-based, and cookie-based attacks. In each type, attackers manipulate inputs in different ways to exploit server-side vulnerabilities and traverse directories.<\/p>"},{"question":"How can Directory Traversal Attacks be prevented?","answer":"<p>Directory Traversal Attacks can be prevented through robust input validation, proper access control, and the principle of least privilege. This involves disallowing certain inputs like \"..\" or \"\/\", not relying solely on the supplied file path for user authorization, and running the application with the least privileges necessary.<\/p>"},{"question":"How do Directory Traversal Attacks compare with similar terms like Remote File Inclusion (RFI) and Local File Inclusion (LFI)?","answer":"<p>While Directory Traversal Attacks exploit vulnerabilities to access unauthorized files and directories, Remote File Inclusion (RFI) involves an attacker uploading a malicious script into a website's server, and Local File Inclusion (LFI) manipulates a website into executing or revealing the contents of files on the web server.<\/p>"},{"question":"What are the future perspectives and technologies related to Directory Traversal Attacks?","answer":"<p>Future perspectives suggest that as web development evolves, the methods to perform Directory Traversal Attacks may become more sophisticated. Web application firewalls, anomaly detection systems, and machine learning algorithms could play a significant role in future mitigation strategies against such attacks.<\/p>"},{"question":"How do Proxy Servers help with Directory Traversal Attacks?","answer":"<p>Proxy servers, like OneProxy, can serve as an additional layer of security against Directory Traversal Attacks. By filtering requests and responses between the client and the server, they can help detect unusual patterns or signs of Directory Traversal Attacks, preventing them from reaching the server.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki\/476846","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/wiki\/476846\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/media\/476847"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/tr\/wp-json\/wp\/v2\/media?parent=476846"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}