> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# Directory / Path Traversal

> Recursos cross-platform para Directory / Path Traversal: máquinas HTB, labs PortSwigger y rooms TryHackMe curados, con writeups validados y skills relacionadas.

# Directory / Path Traversal

Esta página agrega los **recursos para practicar Directory / Path Traversal** de forma cross-platform: máquinas retiradas de Hack The Box, labs de PortSwigger Web Security Academy y rooms de TryHackMe, más recursos curados (HackTricks, PortSwigger, etc.) y skills relacionadas.

## Recursos curados

| Fuente      | Enlace                                                                                                               |
| ----------- | -------------------------------------------------------------------------------------------------------------------- |
| PortSwigger | [https://portswigger.net/web-security/file-path-traversal](https://portswigger.net/web-security/file-path-traversal) |

## Máquinas HTB que practican Directory / Path Traversal (4)

| Máquina                                        | SO      | Dificultad                                       |
| ---------------------------------------------- | ------- | ------------------------------------------------ |
| [Arctic](/htb/machines/windows/facil/arctic)   | Windows | <span className="dbadge dbadge-easy">EASY</span> |
| [Blunder](/htb/machines/linux/facil/blunder)   | Linux   | <span className="dbadge dbadge-easy">EASY</span> |
| [Feline](/htb/machines/linux/dificil/feline)   | Linux   | <span className="dbadge dbadge-hard">HARD</span> |
| [ServMon](/htb/machines/windows/facil/servmon) | Windows | <span className="dbadge dbadge-easy">EASY</span> |

## Labs PortSwigger que practican Directory / Path Traversal (8)

| Lab                                                                                                                                                       | Dificultad                                                 | Topic                       | Oficial                                                                                                        |
| --------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | --------------------------- | -------------------------------------------------------------------------------------------------------------- |
| [File path traversal, simple case](/portswigger/labs/file-path-traversal/simple)                                                                          | <span className="dbadge dbadge-easy">APPRENTICE</span>     | Directory / Path Traversal  | [Abrir](https://portswigger.net/web-security/file-path-traversal/lab-simple)                                   |
| [File path traversal, traversal sequences blocked with absolute path bypass](/portswigger/labs/file-path-traversal/absolute-path-bypass)                  | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Directory / Path Traversal  | [Abrir](https://portswigger.net/web-security/file-path-traversal/lab-absolute-path-bypass)                     |
| [File path traversal, traversal sequences stripped non-recursively](/portswigger/labs/file-path-traversal/sequences-stripped-non-recursively)             | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Directory / Path Traversal  | [Abrir](https://portswigger.net/web-security/file-path-traversal/lab-sequences-stripped-non-recursively)       |
| [File path traversal, traversal sequences stripped with superfluous URL-decode](/portswigger/labs/file-path-traversal/superfluous-url-decode)             | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Directory / Path Traversal  | [Abrir](https://portswigger.net/web-security/file-path-traversal/lab-superfluous-url-decode)                   |
| [File path traversal, validation of file extension with null byte bypass](/portswigger/labs/file-path-traversal/validate-file-extension-null-byte-bypass) | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Directory / Path Traversal  | [Abrir](https://portswigger.net/web-security/file-path-traversal/lab-validate-file-extension-null-byte-bypass) |
| [File path traversal, validation of start of path](/portswigger/labs/file-path-traversal/validate-start-of-path)                                          | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Directory / Path Traversal  | [Abrir](https://portswigger.net/web-security/file-path-traversal/lab-validate-start-of-path)                   |
| [JWT authentication bypass via kid header path traversal](/portswigger/labs/jwt/jwt-authentication-bypass-via-kid-header-path-traversal)                  | <span className="dbadge dbadge-medium">PRACTITIONER</span> | JWT (JSON Web Tokens)       | [Abrir](https://portswigger.net/web-security/jwt/lab-jwt-authentication-bypass-via-kid-header-path-traversal)  |
| [Web shell upload via path traversal](/portswigger/labs/file-upload/file-upload-web-shell-upload-via-path-traversal)                                      | <span className="dbadge dbadge-medium">PRACTITIONER</span> | File Upload Vulnerabilities | [Abrir](https://portswigger.net/web-security/file-upload/lab-file-upload-web-shell-upload-via-path-traversal)  |

## Rooms TryHackMe que practican Directory / Path Traversal (5)

| Room                                                                                      | Dificultad                                         | Tipo        | Acceso  | Oficial                                                                     |
| ----------------------------------------------------------------------------------------- | -------------------------------------------------- | ----------- | ------- | --------------------------------------------------------------------------- |
| [Advent of Cyber 3 (2021)](/tryhackme/rooms/adventofcyber3)                               | <span className="dbadge dbadge-easy">EASY</span>   | Walkthrough | 🟢 Free | [Abrir](https://tryhackme.com/room/adventofcyber3)                          |
| [Badbyte](/tryhackme/rooms/badbyte)                                                       | <span className="dbadge dbadge-easy">EASY</span>   | Walkthrough | 🟢 Free | [Abrir](https://tryhackme.com/room/badbyte)                                 |
| [File Inclusion](/tryhackme/rooms/fileinc)                                                | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🔵 VIP  | [Abrir](https://tryhackme.com/room/fileinc)                                 |
| [File Inclusion, Path Traversal](/tryhackme/rooms/filepathtraversal)                      | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🔵 VIP  | [Abrir](https://tryhackme.com/room/filepathtraversal)                       |
| [Splunk Basics - Did you SIEM?](/tryhackme/rooms/splunkforloganalysis-aoc2025-x8fj2k4rqp) | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🟢 Free | [Abrir](https://tryhackme.com/room/splunkforloganalysis-aoc2025-x8fj2k4rqp) |

## Skills relacionadas

* [/skills/lfi](/skills/lfi)

***

← [Volver al glosario completo](/glosario)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"Directory / Path Traversal","termCode":"directory-traversal","inLanguage":"es","url":"https://rootea.es/skills/directory-traversal","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Glosario táctico de pentesting","url":"https://rootea.es/glosario"}}`}
</script>

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"ItemList","name":"Máquinas HTB que practican Directory / Path Traversal","numberOfItems":4,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://rootea.es/htb/machines/windows/facil/arctic","name":"Arctic"},{"@type":"ListItem","position":2,"url":"https://rootea.es/htb/machines/linux/facil/blunder","name":"Blunder"},{"@type":"ListItem","position":3,"url":"https://rootea.es/htb/machines/linux/dificil/feline","name":"Feline"},{"@type":"ListItem","position":4,"url":"https://rootea.es/htb/machines/windows/facil/servmon","name":"ServMon"}]}`}
</script>

*Última actualización: 2026-06-07*
