offensive-tools/web-app/dotdotpwn/SKILL.md
Directory traversal vulnerability fuzzer for web servers and applications. Use when testing for path traversal and LFI vulnerabilities across HTTP, FTP, and TFTP services.
npx skillsauth add aeondave/malskill dotdotpwnInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Directory traversal fuzzer — test for path traversal across HTTP, FTP, TFTP.
apt install dotdotpwn
# HTTP traversal
dotdotpwn -m http -h target.com -x 80
# HTTP with specific URL
dotdotpwn -m http -h target.com -U "http://target.com/page?file=TRAVERSAL"
# FTP
dotdotpwn -m ftp -h target.com -x 21 -u user -p pass
| Flag | Purpose |
|------|---------|
| -m MODULE | Module: http/http-url/ftp/tftp/payload |
| -h HOST | Target host |
| -x PORT | Target port |
| -U URL | URL with TRAVERSAL placeholder |
| -u USER | Username (FTP) |
| -p PASS | Password (FTP) |
| -f FILE | Target file (e.g., /etc/passwd) |
| -d N | Traversal depth (default: 6) |
| -t N | Time between requests (ms) |
| -q | Quiet mode |
| -s | Stop on first found |
HTTP-URL traversal with custom path:
dotdotpwn -m http-url -h target.com -U "http://target.com/download.php?file=TRAVERSAL" -f /etc/passwd -d 8 -q
Windows target:
dotdotpwn -m http -h target.com -f "windows/system32/cmd.exe" -d 6
| File | When to load |
|------|--------------|
| references/ | Encoding bypass and Windows path notes |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.