Post Ax5qExCRnY87ciMkoS by tychotithonus@infosec.exchange
 (DIR) More posts by tychotithonus@infosec.exchange
 (DIR) Post #Ax5qEuWBlh8fJ4ZyfQ by tychotithonus@infosec.exchange
       2025-08-11T21:59:17Z
       
       1 likes, 0 repeats
       
       Infosec community: Why are we getting so many ../ vulns?Teens entering CS programs: What's a directory?The cloud "pulls up the ladder". It robs future generations of the ability to understand what was made.
       
 (DIR) Post #Ax5qEwGfGNuQjVKbkO by david_chisnall@infosec.exchange
       2025-08-12T12:01:54Z
       
       0 likes, 0 repeats
       
       @tychotithonus Directory traversal vulnerabilities are caused by treating paths as strings, rather than ordered collections of capabilities.  As with SQL injection, they exist because the default APIs are poorly designed ones that encourage concatenating trusted and untrusted strings.
       
 (DIR) Post #Ax5qExCRnY87ciMkoS by tychotithonus@infosec.exchange
       2025-08-12T12:13:02Z
       
       1 likes, 0 repeats
       
       @david_chisnall That's a remarkably cogent way to summarize the technical nature of the problem, and the analogy is apt. Thanks for this!