Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

9
  • 5
    The answers below detail what's happening, how to reproduce it intentionally, and how to fix it, but they don't mention why it happened. Since .. can be used in a path to indicate 'go up one folder', I would hazard a guess that somewhere along the line, some program or script concatenated two strings to create a path, one ended with .., and the next began with .., and since it used one of the techniques mentioned below, it succeeded in creating the path, even though it was missing the folder separator between them.
    – 3D1T0R
    Commented Oct 31, 2018 at 20:58
  • 6
    strange things will also happen if you create a folder with only spaces in its name
    – phuclv
    Commented Nov 1, 2018 at 4:32
  • 7
    Is this server on the internet? Just to warn you I regularly see hack attempts on internet facing web servers requesting: GET /....\\....\\....\\....\\....\\....\\....\\....\\....\\winnt\\win.ini. Clearly there is/was some vulnerability somewhere that this attempts to exploit.
    – Andy Brown
    Commented Nov 2, 2018 at 16:11
  • 5
    @AndyBrown much more likely that's .., not ..... It's simply a way to traverse to \winnt regardless of the depth of the starting point (the web root), so long as the starting point is less than 9 levels deep. It relies on the fact that going .. from the root directory leaves you at the root directory.
    – hobbs
    Commented Nov 2, 2018 at 17:32
  • 6
    @hobbs That's a copy and paste from the Apache access log on linux. Definitely 4 dots in there. There are other hack attempts logged that do use .. which was why I found this one rather odd.
    – Andy Brown
    Commented Nov 3, 2018 at 9:47