Try adding %00 to bypass the added extension on the server side. (Works on PHP < 5.3)
You can even add? to bypass it.
If you can't read php files: php://filter/convert.base64-encode/resource=index
Try reading important files from the system other than passwd. Enumeration might help in determining which files might be important. Maybe try checking the config files for the web app