← Back to Pakistan Cyber Tour

Annex 07 — Server Configuration Disclosure

Pakistan OSINT Operation — 01 March 2026 — LUMS phpinfo.php + version leaks across all targets

LUMS — phpinfo.php (Critical Disclosure)

URL: https://lums.edu.pk/phpinfo.php — 96,738 bytes (complete PHP configuration dump)

Server Identity

Hostname: lumswebsite-websrv1
System:   Linux lumswebsite-websrv1 5.4.17-2136.350.3.2.el8uek.x86_64 #3 SMP
Kernel:   Oracle Unbreakable Enterprise Kernel (UEK)
OS:       Red Hat Enterprise Linux 8.10 (Ootpa)
Arch:     x86_64

Web Stack

ComponentVersion
Apache2.4.66 (codeit)
OpenSSL3.5.4
PHP8.1.34
PHP SAPIFPM/FastCGI
PHP Build DateDecember 16, 2025
Config Path/etc/php.ini

PHP Extensions (Security-Relevant)

ExtensionRiskNotes
SSH2HIGHSSH connection library — server-to-server pivoting potential
LDAPHIGHLDAP client — connects to directory services (Active Directory?)
MySQL (mysqlnd)MEDIUMDatabase connectivity
mcryptMEDIUMDeprecated — may indicate legacy code with weak encryption
SOAPMEDIUMWeb service client — may call internal APIs
cURLMEDIUMHTTP client — SSRF potential
GDLOWImage processing
SodiumLOWModern cryptography

Additional LUMS Disclosures

FileSizeContent
/README.md3,205 bytesDrupal README — CMS confirmed
/robots.txt2,027 bytesStandard Drupal robots.txt

Exploitation Potential

Server Version Disclosures Across All Targets

TargetServerVersionRisk
qau.edu.pknginx1.14.1HIGH — 2018 release, many known CVEs
opendata.com.pknginx1.12.2HIGH — 2017 release, severely outdated
aiou.edu.pkApache2.4.41 (Ubuntu)MEDIUM — 2019 release
lums.edu.pkApache2.4.66 (codeit)LOW — relatively recent
ep.gov.pkIIS10.0LOW — current Windows Server
uos.edu.pkPHP/8.2.30 (header leak)MEDIUM — PHP version in response header

Technology Disclosures

TargetTechnologyDisclosed Via
uos.edu.pkLaravel (PHP framework)Blade-template 404 page
uos.edu.pkPleskLinServer header
ep.gov.pk / hec.gov.pkASP.NETX-Powered-By header
balochistan.gov.pk / sitWordPress + ElementorPage content + API
qau.edu.pkWordPressAPI response
aiou.edu.pkDrupal/user/login page
lums.edu.pkDrupalREADME.md content

Outdated Software Summary

SoftwareDeployedCurrentAge
nginx (QAU)1.14.11.27.x~7 years old
nginx (opendata)1.12.21.27.x~8 years old
Apache (AIOU)2.4.412.4.62+~6 years old
CKAN (opendata)2.8.32.11.x~5 years old