← Back to Pakistan Cyber Tour

Annex 03 — University Intelligence

Pakistan OSINT Operation — 01 March 2026 — QAU, PU, LUMS, AIOU, UOS

5Universities Probed
17.4 MBTotal Data Extracted
18,460URLs (PU Sitemap)
0Additional WAF Deployed (Wartime)

Pakistani universities represent the most exposed segment of Pakistan's digital infrastructure during wartime. While government and military sites were taken offline or placed behind WAFs, universities received no additional protection. Five universities were deeply probed; two (QAU and PU) were subjected to complete data dumps.

Only universities with Cloudflare or Sucuri WAFs resisted reconnaissance. Those without WAFs were fully accessible — no exceptions.

QAU — Quaid-i-Azam University, Islamabad

Pakistan's #1 ranked university (QS World Rankings)

Data TypeCountSizeNotable
Pages2002.4 MBFull HTML including staff listings
Posts4841.4 MBNews, announcements, academic notices
Media603 items200 KBDirect download URLs for all uploads
Categories164179 KBFull taxonomy tree
Search Results1,5451.2 MB43 keyword searches
HTML Pages161.3 MBAdmin, webmail, staff, departments
Total6.6 MB

Organizational Structure Discovered

Academic Faculties: Natural Sciences, Biological Sciences, Social Sciences, Pharmacy

Administrative Units with documented staff:

QAU Internal PBX Mapping

Extension range: 9064-xxxx
Registrar area:   9064-4046 to 9064-4141
Examination area: 9064-4034 to 9064-4096
ICT area:         9064-3231 to 9064-3247
Security:         9064-2028, 9064-2090
International:    +92-51-9064-xxxx

Credential Attack Surface

PU — University of the Punjab, Lahore

Pakistan's largest and oldest university (established 1882) — Custom PHP CMS

Data TypeFilesSizeNotable
Sitemap XML1523 KB18,460 URLs
HTML pages80+7.5 MBAdmin, departments, services
Department pages191.4 MBFull faculty/research data
Total1018.3 MB

Sitemap Analysis (18,460 URLs)

CategoryURLs%
result9,44251.1%
faculty4,65525.2%
IT3,32418.0%
department2,47713.4%
admission1,3057.1%
research4182.3%
admin1931.0%
finance / library / tender / api1480.8%

Admin section (/admin/) returns HTTP 200 (82 KB) with no authentication. Webmail at /mail/ returns "Web Mail: University of the Punjab" (32 KB). Full administrative staff listing at /home/administrative_staff/ (31 KB) and organizational chart at /home/Admin_structure/ (28 KB).

Departments Scraped (19 complete)

Zoology (176 KB), Molecular Biology (153 KB), Microbiology & Molecular Genetics (151 KB), Hailey College of Commerce (133 KB), Social & Cultural Studies (82 KB), Library & Information Management (74 KB), History & Pakistan Studies (71 KB), Clinical Psychology (68 KB), Space Science (60 KB), Islamic Studies (60 KB), Punjab University College of IT (49 KB), plus 8 additional departments.

LUMS — Lahore University of Management Sciences

phpinfo.php exposure — complete server stack disclosure (102 KB)

Full analysis: Annex 07 — Server Disclosure

AIOU — Allama Iqbal Open University

FieldValue
ServerApache/2.4.41 (Ubuntu)
CMSDrupal
Login/user/login exposed
APIs probed/api/, /api/v1/, /api/v2/, /graphql

UOS — University of Sargodha

FieldValue
ServerCloudflare + PleskLin backend
PHP8.2.30 (disclosed in response headers)
FrameworkLaravel (identified from Blade-template 404 page)
Login/login — 5.3 KB real login page
Found directories/downloads/ (236 KB), /directory/ (199 KB)

University Security Posture Comparison

UniversityWAFCMSAPI ExposedAdmin AccessWebmailData Extracted
QAUNONEWordPressFULLYESYES (Roundcube)6.6 MB
PUNONECustom PHPN/AYESYES8.3 MB
LUMSNONEDrupalNoNoNo102 KB (phpinfo!)
AIOUNONEDrupalProbedNoNoMinimal
UOSCloudflareLaravelBlockedNoNoMinimal
NUSTCloudflareBlockedBlockedBlockedNone
COMSATSCloudflareBlockedBlockedBlockedNone