Three attacks where nobody breaks anything - they just walk through a door someone left unlocked.
Look at them side by side and you see the same trick in different wrapping. All three are ways to walk through a door that's already unlocked - you just have to find it and press the handle. No cracking ciphers, no weeks compiling exploit code. Just a system that trusts too literally whatever you feed it, or the person who tells it he belongs.
Path traversal (literally 'passing through the path') lives in the most banal thing in the world - a file name. When a site lets you upload a picture or open a document by address, it expects an ordinary name. Feed it a string of '../' instead (go up one folder) and if the system doesn't check exactly what you're handing it, you climb out of the allowed room straight into passwords, settings, someone else's data - everything the server keeps separate, but not locked tightly enough.
Symlink is short for 'symbolic link' - a shortcut file that, instead of holding data, points to another file somewhere else in the system. A useful tool everywhere in computing, until someone uses it against you. The attack is simple: you leave a file with an innocent name that actually points to someone else's sensitive file. A program with high privileges that doesn't check whether the file in front of it is real or just an arrow opens the arrow and, without meaning to, touches exactly what it shouldn't reach.
Social engineering (literally 'social engineering') is the only one of the three that never touches code at all. The target is the person behind the support desk, not the system behind him. A call that sounds urgent, a story that sounds plausible, the light tone of a 'colleague' who forgot his password - and the door opens voluntarily, because the company's procedures rely on a well-meaning employee who wants to help fast.
The shape says a lot
Here's the trap: an industry that has poured billions into firewall-grade defenses (defensive walls that filter traffic from outside), encryption, two-factor authentication - and the most successful breaches slip past all of it, through one file-name field nobody bothered to check all the way, or through one person who just wanted to get the job done.
That's why when I hear about a "secure system", my first question isn't how strong the encryption is. I ask who checks the input character by character, and who has the right to say "no" to a colleague on the phone, even when he sounds convincing. Technology guards the door. People decide whether to open it.