Skip to content

What it blocks

File access

Someone tries to read private files on your website.

What it is

Addresses that try to climb out of your website's folder, ask for the server's own files, or make your site load a file from somewhere else.

  • ../../etc/passwd in an address
  • A request for .env or .git
  • A page asked to include a file from another website

Why it matters

Configuration files hold passwords and keys. One readable file can be enough to take over the site.

When it stops a real visitor

Rare for a real visitor. If your site has a real address that looks like this, mark the request as real.

What you will see most

The request tried to climb out of the website's folder.
The address used ../ to reach files above the website.
The request tried to climb out of the website's folder.
The address used ../ to reach files above the website.
The request asked for one of the server's own files.
The request named a system file, such as the list of user accounts.
The request asked for a file that should never be public.
It asked for a file that holds passwords or settings, such as .env or .git. A real visitor never needs one.
All 8 rules in this kind, as the rule set names them

For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.

  • 930100Path Traversal Attack (/../) or (/.../)
  • 930110Path Traversal Attack (/../) or (/.../)
  • 930120OS File Access Attempt
  • 930130Restricted File Access Attempt
  • 930140Restricted File Access Attempt: AI Coding Assistant Artifact
  • 931100Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address
  • 931110Possible Remote File Inclusion (RFI) Attack: Common RFI Vulnerable Parameter Name used w/URL Payload
  • 931120Possible Remote File Inclusion (RFI) Attack: URL Payload Used w/Trailing Question Mark Character (?)