The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31dc7c349edc7c349eb0d3026b
Apache Status Apache Server Status for alsa.servtest.fr (via 127.0.0.1) Server Version: Apache/2.4.6 (CentOS) Server MPM: event Server Built: Mar 24 2022 14:57:57 Current Time: Tuesday, 21-Jun-2022 09:45:54 CEST Restart Time: Monday, 20-Jun-2022 22:19:52 CEST Parent Server Config. Generation: 2 Parent Server MPM Generation: 1 Server uptime: 11 hours 26 minutes 2 seconds Server load: 0.16 0.16 0.11 Total accesses: 1424 - Total Traffic: 3.2 MB CPU Usage: u24.96 s25.47 cu0 cs0 - .123% CPU load .0346 requests/sec - 80 B/second - 2324 B/request 5 requests currently being processed, 95 idle workers PIDConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 99720yes223000 99730yes322000 105510yes025000 99740yes025000 Sum0 595000 _______________WW___________________________WW___R______________ ____________________________________............................ ................................................................ ................................................................ ................................................................ ................................................................ ................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqConnChildSlotClientVHostRequest 0-199720/1/8_ 0.0038210.00.000.01 45.32.195.186localhost:80GET / HTTP/1.1 0-199720/1/8_ 0.00380130.00.000.01 127.0.0.1localhost:80GET /monitoring/index.php HTTP/1.0 0-199720/1/8_ 0.013513630.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_virtualhost.cgi HTTP/1.1 0-199720/1/8_ 0.17594570.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_letshap.cgi HTTP/1.1 0-199720/1/8_ 0.18524230.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_letshap.cgi HTTP/1.1 0-199720/1/8_ 0.194000.00.000.01 80.247.233.242alsa.servtest.fr:80GET /favicon.ico HTTP/1.1 0-199720/1/8_ 0.19352990.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /index.cgi?action=accueil HTTP/1.1 0-199720/0/7_ 17.283833810.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001POST /gestion_domaine.cgi HTTP/1.1 0-199720/0/7_ 17.063835130.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001POST / HTTP/1.1 0-199720/0/6_ 16.2438310.00.000.01 127.0.0.1alsatis-vm2.monitoring.nfrance.GET /monitoring/php80/index.php HTTP/1.1 0-199720/0/7_ 17.0638300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /Images/oxygen/actions/users.png HTTP/1.1 0-199720/0/7_ 17.0838310.00.000.06 127.0.0.1 0-199720/0/7_ 17.0638300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /scripts/jquery.complexify.js?v=1.1 HTTP/1.1 0-199720/1/8_ 0.21000.00.000.03 167.94.138.120localhost:80GET / HTTP/1.1 0-199720/1/8_ 0.22060.00.020.03 127.0.0.1 0-199720/0/7W 17.11000.00.000.01 45.79.93.245alsa.servtest.fr:80GET / HTTP/1.1 0-199720/0/7W 17.06000.00.000.01 45.79.93.245alsa.servtest.fr:80GET /info.php HTTP/1.1 0-199720/1/8_ 0.22000.00.000.01 45.79.93.245alsa.servtest.fr:80GET /telescope/requests HTTP/1.1 0-199720/0/7_ 17.1138300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /scripts/certifs.js?v=1.0 HTTP/1.1 0-199720/1/8_ 0.21650.00.100.10 89.175.184.250alsa.servtest.fr:80GET / HTTP/1.1 0-199720/0/7_ 17.0738320.00.000.01 80.247.233.242localhost:80GET /webmail/plugins/jqueryui/js/i18n/datepicker-fr.js?s=165502 0-199720/1/8_ 0.21140.00.100.11 178.62.23.86alsa.servtest.fr:80GET / HTTP/1.1 0-199720/1/8_ 0.21000.00.000.01 178.62.23.86alsa.servtest.fr:80GET /config.json HTTP/1.1 0-199720/0/7_ 17.1238390.00.000.04 127.0.0.1 0-199720/0/7_ 17.08383100.00.000.05 127.0.0.1 1-199730/0/15_ 17.2138310.00.000.05 80.247.233.242localhost:80GET /sysusage/ HTTP/1.1 1-199730/0/15_ 17.2038340.00.000.05 127.0.0.1 1-199730/0/17_ 17.2038300.00.000.03 127.0.0.1 1-199730/0/14_ 17.1938340.00.000.04 127.0.0.1 1-199730/1/14_ 0.003694300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001POST /assistant.cgi HTTP/1.1 1-199730/0/13_ 17.183831580.00.000.02 80.247.233.242localhost:80GET /webmail/ HTTP/1.1 1-199730/1/16_ 0.013562950.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /index.cgi?action=accueil HTTP/1.1 1-199730/1/15_ 0.062802150.00.030.06 127.0.0.1 1-199730/1/16_ 0.1018900.00.000.02 80.247.233.242alsa.servtest.fr:80GET /robots.txt HTTP/1.1 1-199730/1/15_ 0.1018800.00.000.02 80.247.233.242alsa.servtest.fr:80GET /favicon.ico HTTP/1.1 1-199730/1/16_ 0.111833960.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /index.cgi?action=accueil HTTP/1.1 1-199730/1/15_ 0.111793390.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_acces.cgi HTTP/1.1 1-199730/1/16_ 0.131473130.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_virtualhost.cgi HTTP/1.1 1-199730/1/16_ 0.151043510.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_letshap.cgi HTTP/1.1 1-199730/1/16_ 0.1860449560.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /apply.pl?vhost=alsa.servtest.fr&action=certifs&domaine=ser 1-199730/1/15_ 0.168040.00.000.02 127.0.0.1alsatis-vm2.monitoring.nfrance.GET /monitoring/php80/index.php HTTP/1.1 1-199730/1/16_ 0.193500.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /favicon.ico HTTP/1.1 1-199730/1/15_ 0.21000.00.000.02 178.62.23.86alsa.servtest.fr:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-199730/1/16_ 0.21030.00.100.14 178.62.23.86alsa.servtest.fr:80GET / HTTP/1.1 1-199730/0/14W 17.17000.00.000.01 45.79.93.245alsa.servtest.fr:80GET /server-status HTTP/1.1 1-199730/2/17_ 0.21000.00.000.02 45.79.93.245alsa.servtest.fr:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-199730/0/14_ 17.1738300.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /scripts/assistant.js?v=5.9 HTTP/1.1 1-199730/0/15_ 17.2738300.00.000.02 80.247.233.242localhost:80GET /sysusage/alsatis-vm2.lan.nfrance.net/start.html HTTP/1.1 1-199730/0/15_ 17.2738310.00.000.02 127.0.0.1 1-199730/0/14W 17.18000.00.000.01 45.79.93.245alsa.servtest.fr:80GET /?rest_route=/wp/v2/users/ HTTP/1.1 2-1105510/1/13_ 0.0528000.00.000.01 80.247.233.242alsa.servtest.fr:80GET /robots.txt HTTP/1.1 2-1105510/2/12_ 0.26000.00.000.01 178.62.23.86alsa.servtest.fr:80GET /.DS_Store HTTP/1.1 2-1105510/1/12_ 0.2240120.00.020.04 127.0.0.1 2-1105510/2/13_ 0.27000.00.000.04 167.94.138.120localhost:80GET / HTTP/1.1 2-1105510/1/12_ 0.24293880.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_messagerie.cgi HTTP/1.1 2-1105510/1/11_ 0.08250160.00.000.04 80.247.233.242localhost:80GET /goaccess_stats/alsa.servtest.fr/ HTTP/1.1 2-1105510/1/1
The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31dc7c349edc7c349eee49ed84
Apache Status Apache Server Status for alsa.servtest.fr (via 127.0.0.1) Server Version: Apache/2.4.6 (CentOS) Server MPM: event Server Built: Mar 24 2022 14:57:57 Current Time: Tuesday, 21-Jun-2022 09:45:54 CEST Restart Time: Monday, 20-Jun-2022 22:19:52 CEST Parent Server Config. Generation: 2 Parent Server MPM Generation: 1 Server uptime: 11 hours 26 minutes 1 second Server load: 0.18 0.17 0.12 Total accesses: 1412 - Total Traffic: 3.0 MB CPU Usage: u32.98 s34.2 cu0 cs0 - .163% CPU load .0343 requests/sec - 76 B/second - 2229 B/request 2 requests currently being processed, 98 idle workers PIDConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 99720yes025000 99730yes025000 105511yes223000 99740yes025000 Sum1 298000 __________________________________________________________W_____ ________W___________________________............................ ................................................................ ................................................................ ................................................................ ................................................................ ................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqConnChildSlotClientVHostRequest 0-199720/1/8_ 0.0038110.00.000.01 45.32.195.186localhost:80GET / HTTP/1.1 0-199720/1/8_ 0.00380130.00.000.01 127.0.0.1localhost:80GET /monitoring/index.php HTTP/1.0 0-199720/1/8_ 0.013503630.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_virtualhost.cgi HTTP/1.1 0-199720/1/8_ 0.17594570.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_letshap.cgi HTTP/1.1 0-199720/1/8_ 0.18514230.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_letshap.cgi HTTP/1.1 0-199720/1/8_ 0.193900.00.000.01 80.247.233.242alsa.servtest.fr:80GET /favicon.ico HTTP/1.1 0-199720/1/8_ 0.19342990.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /index.cgi?action=accueil HTTP/1.1 0-199720/0/7_ 17.283833810.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001POST /gestion_domaine.cgi HTTP/1.1 0-199720/0/7_ 17.063835130.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001POST / HTTP/1.1 0-199720/0/6_ 16.2438310.00.000.01 127.0.0.1alsatis-vm2.monitoring.nfrance.GET /monitoring/php80/index.php HTTP/1.1 0-199720/0/7_ 17.0638300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /Images/oxygen/actions/users.png HTTP/1.1 0-199720/0/7_ 17.0838310.00.000.06 127.0.0.1 0-199720/0/7_ 17.0638300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /scripts/jquery.complexify.js?v=1.1 HTTP/1.1 0-199720/0/7_ 17.0938310.00.000.02 127.0.0.1 0-199720/0/7_ 17.0638300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /Images/nfsite/ariane.png HTTP/1.1 0-199720/0/7_ 17.113833560.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_virtualhost.cgi HTTP/1.1 0-199720/0/7_ 17.063833950.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_acces.cgi HTTP/1.1 0-199720/0/7_ 17.073833280.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_domaine.cgi HTTP/1.1 0-199720/0/7_ 17.1138300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /scripts/certifs.js?v=1.0 HTTP/1.1 0-199720/1/8_ 0.21550.00.100.10 89.175.184.250alsa.servtest.fr:80GET / HTTP/1.1 0-199720/0/7_ 17.0738320.00.000.01 80.247.233.242localhost:80GET /webmail/plugins/jqueryui/js/i18n/datepicker-fr.js?s=165502 0-199720/1/8_ 0.21040.00.100.11 178.62.23.86alsa.servtest.fr:80GET / HTTP/1.1 0-199720/0/7_ 17.0738300.00.000.01 80.247.233.242localhost:80GET /webmail/plugins/jqueryui/js/i18n/datepicker-fr.js?s=165502 0-199720/0/7_ 17.1238390.00.000.04 127.0.0.1 0-199720/0/7_ 17.08383100.00.000.05 127.0.0.1 1-199730/0/15_ 17.2138310.00.000.05 80.247.233.242localhost:80GET /sysusage/ HTTP/1.1 1-199730/0/15_ 17.2038340.00.000.05 127.0.0.1 1-199730/0/17_ 17.2038300.00.000.03 127.0.0.1 1-199730/0/14_ 17.1938340.00.000.04 127.0.0.1 1-199730/1/14_ 0.003694300.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001POST /assistant.cgi HTTP/1.1 1-199730/0/13_ 17.183831580.00.000.02 80.247.233.242localhost:80GET /webmail/ HTTP/1.1 1-199730/1/16_ 0.013562950.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /index.cgi?action=accueil HTTP/1.1 1-199730/1/15_ 0.062792150.00.030.06 127.0.0.1 1-199730/1/16_ 0.1018800.00.000.02 80.247.233.242alsa.servtest.fr:80GET /robots.txt HTTP/1.1 1-199730/1/15_ 0.1018800.00.000.02 80.247.233.242alsa.servtest.fr:80GET /favicon.ico HTTP/1.1 1-199730/1/16_ 0.111823960.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /index.cgi?action=accueil HTTP/1.1 1-199730/1/15_ 0.111783390.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_acces.cgi HTTP/1.1 1-199730/1/16_ 0.131463130.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_virtualhost.cgi HTTP/1.1 1-199730/1/16_ 0.151043510.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_letshap.cgi HTTP/1.1 1-199730/1/16_ 0.1859449560.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /apply.pl?vhost=alsa.servtest.fr&action=certifs&domaine=ser 1-199730/1/15_ 0.167940.00.000.02 127.0.0.1alsatis-vm2.monitoring.nfrance.GET /monitoring/php80/index.php HTTP/1.1 1-199730/1/16_ 0.193400.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /favicon.ico HTTP/1.1 1-199730/0/14_ 17.163833590.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /index.cgi?action=accueil HTTP/1.1 1-199730/0/15_ 17.2738310.00.000.04 127.0.0.1 1-199730/0/14_ 17.173833600.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /assistant.cgi HTTP/1.1 1-199730/0/15_ 17.2738300.00.000.02 80.247.233.242localhost:80GET /sysusage/sysusage.js HTTP/1.1 1-199730/0/14_ 17.1738300.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /scripts/assistant.js?v=5.9 HTTP/1.1 1-199730/0/15_ 17.2738300.00.000.02 80.247.233.242localhost:80GET /sysusage/alsatis-vm2.lan.nfrance.net/start.html HTTP/1.1 1-199730/0/15_ 17.2738310.00.000.02 127.0.0.1 1-199730/0/14_ 17.183833290.00.000.01 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_messagerie.cgi HTTP/1.1 2-1105510/1/13_ 0.0527900.00.000.01 80.247.233.242alsa.servtest.fr:80GET /robots.txt HTTP/1.1 2-1105510/1/11_ 0.0527900.00.000.01 80.247.233.242alsa.servtest.fr:80GET /favicon.ico HTTP/1.1 2-1105510/1/12_ 0.2239120.00.020.04 127.0.0.1 2-1105510/1/12_ 0.0625010.00.000.04 80.247.233.242localhost:80GET /goaccess_stats/alsa.servtest.fr/ HTTP/1.1 2-1105510/1/12_ 0.24283880.00.000.02 80.247.228.60alsatis-vm2.nfadmin.net:10001GET /gestion_messagerie.cgi HTTP/1.1 2-1105510/1/11_ 0.08249160.00.000.04 80.247.233.242localho