Apache

Apache httpd's flexibility, per-directory .htaccess overrides, extension-based handlers, and a rich module set, is also its misconfiguration surface. Fingerprint it from the Server: Apache header, default error pages, and .htaccess/mod_* behavior, then work this checklist.

What to check#

  • Handler and type mapping: does a handler match an inner extension (shell.php.jpg), is a directory's handler set to execute uploads, or is the PHP handler missing so scripts return as source?
  • .htaccess overrides: where AllowOverride is permissive and a directory is writable (uploads), an attacker-supplied .htaccess changes handlers, rewrites, and auth.
  • Alias and rewrite: do Alias/AliasMatch/mod_rewrite rules build filesystem paths from unconstrained URL captures, allowing traversal into the parent of the mapped directory?
  • MultiViews: is content negotiation enabled, letting an attacker request page and have Apache pick page.php/page.bak, enumerating and disclosing files?

Pages#

References#

  • Apache httpd documentation: mod_mime, mod_alias, mod_rewrite, mod_negotiation, AllowOverride
  • OWASP WSTG: Testing for application platform configuration

Cookie Consent

We use cookies to enhance your experience. Learn more