ODINT Donate
Survey plate · Pakistan Traverse the grid
A01B02C03D04E05F06G07H08PAKISTAN30.79N 69.44E

INV-090027 · Pakistan · published

Annex 07 — Server Configuration Disclosure

LUMS phpinfo.php exposes complete server stack — hostname, RHEL 8.10, PHP 8.1.34, SSH2 and LDAP extensions. Plus all server version disclosures across Pakistan OSINT operation.

ODINT Investigation Team · 2026-04-24

Record
INV-090027
Status
published
Assets
0
Documents
0
Map
Not included

Annex 07 — Server Configuration Disclosure

Pakistan OSINT Operation — 01 March 2026 — LUMS phpinfo.php + version leaks across all targets

LUMS — phpinfo.php (Critical Disclosure)

URL:https://lums.edu.pk/phpinfo.php — 96,738 bytes (complete PHP configuration dump)

Server Identity

Hostname: lumswebsite-websrv1
System: Linux lumswebsite-websrv1 5.4.17-2136.350.3.2.el8uek.x86_64 #3 SMP
Kernel: Oracle Unbreakable Enterprise Kernel (UEK)
OS: Red Hat Enterprise Linux 8.10 (Ootpa)
Arch: x86_64

Web Stack

ComponentVersion
Apache2.4.66 (codeit)
OpenSSL3.5.4
PHP8.1.34
PHP SAPIFPM/FastCGI
PHP Build DateDecember 16, 2025
Config Path/etc/php.ini

PHP Extensions (Security-Relevant)

ExtensionRiskNotes
SSH2HIGHSSH connection library — server-to-server pivoting potential
LDAPHIGHLDAP client — connects to directory services (Active Directory?)
MySQL (mysqlnd)MEDIUMDatabase connectivity
mcryptMEDIUMDeprecated — may indicate legacy code with weak encryption
SOAPMEDIUMWeb service client — may call internal APIs
cURLMEDIUMHTTP client — SSRF potential
GDLOWImage processing
SodiumLOWModern cryptography

Additional LUMS Disclosures

FileSizeContent
/README.md3,205 bytesDrupal README — CMS confirmed
/robots.txt2,027 bytesStandard Drupal robots.txt

Exploitation Potential

  • SSH2 Extension: If PHP scripts can create SSH connections, this server can pivot to other LUMS infrastructure
  • LDAP Extension: LUMS likely uses LDAP for authentication — LDAP injection attacks against web forms could enumerate the directory
  • Kernel Version:5.4.17-2136.350.3.2.el8uek.x86_64 — matchable against kernel CVE databases for local privilege escalation vectors
  • RHEL 8.10: Specific OS version enables precise CVE matching
  • mcrypt: Deprecated PHP extension may indicate legacy code with weak encryption
  • Drupal CMS: Known attack surface (Drupalgeddon history)

Server Version Disclosures Across All Targets

TargetServerVersionRisk
qau.edu.pknginx1.14.1HIGH — 2018 release, many known CVEs
opendata.com.pknginx1.12.2HIGH — 2017 release, severely outdated
aiou.edu.pkApache2.4.41 (Ubuntu)MEDIUM — 2019 release
lums.edu.pkApache2.4.66 (codeit)LOW — relatively recent
ep.gov.pkIIS10.0LOW — current Windows Server
uos.edu.pkPHP/8.2.30 (header leak)MEDIUM — PHP version in response header

Technology Disclosures

TargetTechnologyDisclosed Via
uos.edu.pkLaravel (PHP framework)Blade-template 404 page
uos.edu.pkPleskLinServer header
ep.gov.pk / hec.gov.pkASP.NETX-Powered-By header
balochistan.gov.pk / sitWordPress + ElementorPage content + API
qau.edu.pkWordPressAPI response
aiou.edu.pkDrupal/user/login page
lums.edu.pkDrupalREADME.md content

Outdated Software Summary

SoftwareDeployedCurrentAge
nginx (QAU)1.14.11.27.x~7 years old
nginx (opendata)1.12.21.27.x~8 years old
Apache (AIOU)2.4.412.4.62+~6 years old
CKAN (opendata)2.8.32.11.x~5 years old