Platform

The platform is the web server and the way the service is hosted and exposed: Apache, nginx, IIS, or a Java app server; reverse proxies and CDNs; virtual hosts; the rules that map a URL to a file or a backend; and the handlers that decide whether a file is served, disclosed, or executed. This layer owns a class of vulnerabilities distinct from the application logic (Code) and the language engine (Runtime). The test for whether a bug belongs here: would it still exist if the application source and the language runtime were benign, because the weakness is in server configuration, deployment topology, or how the server resolves and routes requests?

How this area is organized#

The library's organizing rule is to split by the axis you identify first at a given layer, then refine. In application Code that axis is the dangerous primitive; in Runtime it is primitive then language or engine. At the platform layer the thing you identify first is the product: you fingerprint the server, then run that product's misconfiguration checklist. So Platform is organized by product (Apache, nginx, IIS, Tomcat), which is the same principle applied one layer out, not a departure from it. A single general section holds the product-agnostic exposures (a served .git, directory listing, backups, leaked config) so they are not repeated under each product, and a reverse proxy and edge section covers behavior that belongs to the proxy role rather than any one product.

The underlying primitives still run through every product, so each page is tagged with its primitive and the table below gives a primitive-first way in, on top of the product-first tree.

By primitive (cross-reference)#

PrimitiveWhere it appears
Path traversal / mappingApache alias/rewrite, nginx alias off-by-slash, nginx slash normalization, IIS double-decode, proxy normalization mismatch
Source disclosureApache handler, Apache MultiViews, IIS NTFS tricks, general VCS, general backups
Handler / upload to executionApache handler, nginx FastCGI/PHP-FPM, IIS handlers
SSRF / routingnginx variable proxy_pass, proxy_pass and misrouting, origin exposure
Deployment RCETomcat Manager, AJP/Ghostcat
Information exposuregeneral (status endpoints, VCS, backups, listing, config)
Header / identity trustedge header trust

Fingerprint first#

Before the checklists, identify the server: Server/X-Powered-By headers, default error pages, cookie names (JSESSIONID = Java, ASP.NET_SessionId = IIS), header ordering and casing, favicon hashes, and behavior on malformed requests. The fingerprint selects the section.

Sections#

  • General: exposures on any server, status endpoints, .git/VCS, backups, directory listing, leaked config.
  • Apache: handler/type mapping, Alias/mod_rewrite traversal, MultiViews negotiation.
  • nginx: alias off-by-slash, FastCGI/PHP-FPM wiring, variable proxy_pass SSRF, slash normalization.
  • IIS: NTFS filename tricks, double-decode/Unicode traversal, handlers and web.config.
  • Tomcat and Java: AJP/Ghostcat, Manager deployment, path-parameter traversal.
  • Reverse proxy and edge: edge/origin normalization mismatch, origin exposure, edge header trust.

References#

  • Apache httpd and nginx documentation (configuration references)
  • PortSwigger Web Security Academy: Information disclosure, Access control, SSRF

Cookie Consent

We use cookies to enhance your experience. Learn more