The platform is the web server and the way the service is hosted and exposed: Apache, nginx, IIS, or a Java app server; reverse proxies and CDNs; virtual hosts; the rules that map a URL to a file or a backend; and the handlers that decide whether a file is served, disclosed, or executed. This layer owns a class of vulnerabilities distinct from the application logic (Code) and the language engine (Runtime). The test for whether a bug belongs here: would it still exist if the application source and the language runtime were benign, because the weakness is in server configuration, deployment topology, or how the server resolves and routes requests?
How this area is organized#
The library's organizing rule is to split by the axis you identify first at a given layer, then refine. In application Code that axis is the dangerous primitive; in Runtime it is primitive then language or engine. At the platform layer the thing you identify first is the product: you fingerprint the server, then run that product's misconfiguration checklist. So Platform is organized by product (Apache, nginx, IIS, Tomcat), which is the same principle applied one layer out, not a departure from it. A single general section holds the product-agnostic exposures (a served .git, directory listing, backups, leaked config) so they are not repeated under each product, and a reverse proxy and edge section covers behavior that belongs to the proxy role rather than any one product.
The underlying primitives still run through every product, so each page is tagged with its primitive and the table below gives a primitive-first way in, on top of the product-first tree.
By primitive (cross-reference)#
| Primitive | Where it appears |
|---|---|
| Path traversal / mapping | Apache alias/rewrite, nginx alias off-by-slash, nginx slash normalization, IIS double-decode, proxy normalization mismatch |
| Source disclosure | Apache handler, Apache MultiViews, IIS NTFS tricks, general VCS, general backups |
| Handler / upload to execution | Apache handler, nginx FastCGI/PHP-FPM, IIS handlers |
| SSRF / routing | nginx variable proxy_pass, proxy_pass and misrouting, origin exposure |
| Deployment RCE | Tomcat Manager, AJP/Ghostcat |
| Information exposure | general (status endpoints, VCS, backups, listing, config) |
| Header / identity trust | edge header trust |
Fingerprint first#
Before the checklists, identify the server: Server/X-Powered-By headers, default error pages, cookie names (JSESSIONID = Java, ASP.NET_SessionId = IIS), header ordering and casing, favicon hashes, and behavior on malformed requests. The fingerprint selects the section.
Sections#
- General: exposures on any server, status endpoints,
.git/VCS, backups, directory listing, leaked config. - Apache: handler/type mapping,
Alias/mod_rewritetraversal, MultiViews negotiation. - nginx:
aliasoff-by-slash, FastCGI/PHP-FPM wiring, variableproxy_passSSRF, slash normalization. - IIS: NTFS filename tricks, double-decode/Unicode traversal, handlers and
web.config. - Tomcat and Java: AJP/Ghostcat, Manager deployment, path-parameter traversal.
- Reverse proxy and edge: edge/origin normalization mismatch, origin exposure, edge header trust.
References#
- Apache httpd and nginx documentation (configuration references)
- PortSwigger Web Security Academy: Information disclosure, Access control, SSRF