> For the complete documentation index, see [llms.txt](https://heinosass.gitbook.io/leet-sheet/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://heinosass.gitbook.io/leet-sheet/web-app-hacking/server-attacks/server-misconfigurations.md).

# Server Misconfigurations

## Debugging Enabled

Some servers have debugging mode, which allows attackers to view errors, execute code, debug code, etc.

An indication of enabled debugging mode is that you might see a header like XDEBUG. Every debug library is different, but to connect to XDEBUG, you should open an xdebug listener (chromium has one), and send a GET request to the server like /?XDEBUG\_SESSION\_START=somesessionnameitdoesntmatter. Note that the server will connect to you, not the other way around.

This allows you to change server-side code, and you can get RCE.
