we_are_coded.by CODE · The world, decoded
БГ
Concept

Attacks by name (path traversal, symlink, social engineering)

The BasicsUpdated on 16 August 2026we are coded

Three attacks where nobody breaks anything - they just walk through a door someone left unlocked.

Checked on16 August 2026
In short: three attacks where nobody breaks any code. With path traversal you feed "../../" into an address bar or a file field and step outside the folder you're allowed in, straight into someone else's files on the server. With a symlink attack you leave a file that's actually an arrow pointing to another file, and trick the program into opening something it shouldn't. With social engineering you don't touch a system at all - you call someone on support and talk them into opening the door themselves. All three win because nobody checks the obvious.

Look at them side by side and you see the same trick in different wrapping. All three are ways to walk through a door that's already unlocked - you just have to find it and press the handle. No cracking ciphers, no weeks compiling exploit code. Just a system that trusts too literally whatever you feed it, or the person who tells it he belongs.

Path traversal (literally 'passing through the path') lives in the most banal thing in the world - a file name. When a site lets you upload a picture or open a document by address, it expects an ordinary name. Feed it a string of '../' instead (go up one folder) and if the system doesn't check exactly what you're handing it, you climb out of the allowed room straight into passwords, settings, someone else's data - everything the server keeps separate, but not locked tightly enough.

Symlink is short for 'symbolic link' - a shortcut file that, instead of holding data, points to another file somewhere else in the system. A useful tool everywhere in computing, until someone uses it against you. The attack is simple: you leave a file with an innocent name that actually points to someone else's sensitive file. A program with high privileges that doesn't check whether the file in front of it is real or just an arrow opens the arrow and, without meaning to, touches exactly what it shouldn't reach.

Social engineering (literally 'social engineering') is the only one of the three that never touches code at all. The target is the person behind the support desk, not the system behind him. A call that sounds urgent, a story that sounds plausible, the light tone of a 'colleague' who forgot his password - and the door opens voluntarily, because the company's procedures rely on a well-meaning employee who wants to help fast.

None of the three requires a genius - it only requires that someone on the other end doesn't check.

The shape says a lot

Here's the trap: an industry that has poured billions into firewall-grade defenses (defensive walls that filter traffic from outside), encryption, two-factor authentication - and the most successful breaches slip past all of it, through one file-name field nobody bothered to check all the way, or through one person who just wanted to get the job done.

That's why when I hear about a "secure system", my first question isn't how strong the encryption is. I ask who checks the input character by character, and who has the right to say "no" to a colleague on the phone, even when he sounds convincing. Technology guards the door. People decide whether to open it.

The visual is generated code art. No third-party images.
Official primary sources
→CWE-22: Path Traversal (MITRE)→CWE-59: Link Following / symlink (MITRE)→CISA: Avoiding Social Engineering and Phishing Attacks