Apache httpd's flexibility, per-directory .htaccess overrides, extension-based handlers, and a rich module set, is also its misconfiguration surface. Fingerprint it from the Server: Apache header, default error pages, and .htaccess/mod_* behavior, then work this checklist.
What to check#
- Handler and type mapping: does a handler match an inner extension (
shell.php.jpg), is a directory's handler set to execute uploads, or is the PHP handler missing so scripts return as source? - .htaccess overrides: where
AllowOverrideis permissive and a directory is writable (uploads), an attacker-supplied.htaccesschanges handlers, rewrites, and auth. - Alias and rewrite: do
Alias/AliasMatch/mod_rewriterules build filesystem paths from unconstrained URL captures, allowing traversal into the parent of the mapped directory? - MultiViews: is content negotiation enabled, letting an attacker request
pageand have Apache pickpage.php/page.bak, enumerating and disclosing files?
Pages#
- Handler and type mapping:
AddHandler/AddType/SetHandlerexecution and source-disclosure mistakes,.htaccessabuse, and double-extension upload execution. - Alias and rewrite traversal:
Alias/AliasMatch/mod_rewritepath mapping that escapes the intended directory. - MultiViews and content negotiation: abusing
mod_negotiationto enumerate and disclose files.
References#
- Apache httpd documentation: mod_mime, mod_alias, mod_rewrite, mod_negotiation, AllowOverride
- OWASP WSTG: Testing for application platform configuration