Splunk Search

How to search for DR string ../../../../ ??

ShinR
Explorer

Hi everyone,

I just wanted to do a quick search in URLs requested in Splunk but cannot get the directory traversal string  (../../../../ o similar) to stick - it gets stripped from the query.  I've tried using quotes and it seems escaping shouldn't be necessary.  

Any suggestions?

Thanks

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the troublesome query.

---
If this reply helps you, Karma would be appreciated.

ShinR
Explorer

Sorry, here's a simple example:

index=* url="*../../../../*"

or 

index=* "../../../../"

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I believe the problem is attempting to search for a string of minor blocker characters.  You may have better luck using a separate where command.

 

index=foo ```Always use explicit index names```
| where like(url, "../../../../%") ```Like is used instead of match to avoid escaping every character```

 

---
If this reply helps you, Karma would be appreciated.

ShinR
Explorer

Thanks again for the suggestion.  Unfortunately everything between the * and the % gets stripped when I execute the search.  

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The asterisk was a typo.  Please try again without it.  

---
If this reply helps you, Karma would be appreciated.
0 Karma

ShinR
Explorer

Same result unfortunately... does the same thing not happen on your splunk instance?

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It does not happen on my instance (8.1.2)

richgalloway_0-1629115577281.png

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

NatSec
Explorer

I have the same issue on Splunk v8.2.1

Any solution please?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...