This video presents an analysis of disclosed bug bounty reports about write-based path traversal vulnerabilities. Specifically, it’s about what files you should write to show the maximum impact of a path traversal like this, ideally escalating it to RCE.

00:00 Intro
01:29 Writing any file but outside safe directory
06:09 Shell upload
09:35 Shell upload alternative in technologies like Node.js, Golang, Python or Ruby – template overwrite
13:35 .ssh/authorized_keys

