cloudflare
tcp/443
The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31bdf8e5d5bdf8e5d5f8d34d80
Apache Status Apache Server Status for b3yard.com (via 127.0.0.1) Server Version: Apache/2.4.59 (Debian) OpenSSL/3.0.11 Server MPM: prefork Server Built: 2024-04-05T12:02:26 Current Time: Thursday, 02-May-2024 15:55:10 CEST Restart Time: Thursday, 02-May-2024 15:53:19 CEST Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 1 minute 51 seconds Server load: 0.06 0.07 0.17 Total accesses: 121 - Total Traffic: 112 kB - Total Duration: 49 CPU Usage: u.08 s.09 cu0 cs0 - .153% CPU load 1.09 requests/sec - 1033 B/second - 947 B/request - .404959 ms/request 10 requests currently being processed, 0 workers gracefully restarting, 10 idle workers _____CCCCCCCCC___W__............................................ ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-0540400/13/13_ 0.030040.00.010.01 165.227.173.41http/1.1b3yard.com:8443GET /.git/config HTTP/1.1 1-0540410/15/15_ 0.010060.00.010.01 134.209.25.199http/1.1b3yard.com:8443GET /about HTTP/1.1 2-0540420/23/23_ 0.020060.00.020.02 165.227.173.41http/1.1b3yard.com:8443GET /.env HTTP/1.1 3-0540430/19/19_ 0.020060.00.020.02 165.227.173.41http/1.1b3yard.com:8443GET /config.json HTTP/1.1 4-0540440/23/23_ 0.030090.00.020.02 165.227.173.41http/1.1b3yard.com:8443GET /s/832313e28353e2939313e2331323/_/;/META-INF/maven/com.atla 5-0546961/8/8C 0.011041.30.010.01 134.209.25.199http/1.1b3yard.com:8443GET /.env HTTP/1.1 6-0547031/4/4C 0.001011.30.000.00 134.209.25.199http/1.1b3yard.com:8443GET /.git/config HTTP/1.1 7-0547041/3/3C 0.000011.40.000.00 134.209.25.199http/1.1b3yard.com:8443GET /s/832313e28353e2939313e2331323/_/;/META-INF/maven/com.atla 8-0547111/4/4C 0.001031.30.000.00 134.209.25.199http/1.1b3yard.com:8443GET /login.action HTTP/1.1 9-0547121/1/1C 0.001001.40.000.00 165.227.173.41http/1.1b3yard.com:8443GET /telescope/requests HTTP/1.1 10-0547131/2/2C 0.001001.40.000.00 134.209.25.199http/1.1b3yard.com:8443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 11-0547141/1/1C 0.001011.30.000.00 134.209.25.199http/1.1b3yard.com:8443GET /server-status HTTP/1.1 12-0547211/1/1C 0.000001.30.000.00 134.209.25.199http/1.1b3yard.com:8443GET /config.json HTTP/1.1 13-0547221/1/1C 0.000011.30.000.00 134.209.25.199http/1.1b3yard.com:8443GET /telescope/requests HTTP/1.1 14-0547230/1/1_ 0.000000.00.000.00 127.0.0.1http/1.1b3yard.com:8080GET /v2/_catalog HTTP/1.0 15-0547240/1/1_ 0.000000.00.000.00 134.209.25.199http/1.1b3yard.com:8443GET /?rest_route=/wp/v2/users/ HTTP/1.1 16-0547250/1/1_ 0.000000.00.000.00 127.0.0.1http/1.1b3yard.com:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 17-0547260/0/0W 0.000000.00.000.00 127.0.0.1http/1.1b3yard.com:8080GET /server-status HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 42subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 295 seconds, (range: 294...297)index usage: 1%, cache usage: 1%total entries stored since starting: 42total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 30 hit, 12 misstotal removes since starting: 0 hit, 4 miss Apache/2.4.59 (Debian) Server at b3yard.com Port 80
The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb313e317b783e317b78544aa530
Apache Status Apache Server Status for www.b3yard.com (via 127.0.0.1) Server Version: Apache/2.4.59 (Debian) OpenSSL/3.0.11 Server MPM: prefork Server Built: 2024-04-05T12:02:26 Current Time: Thursday, 02-May-2024 15:55:05 CEST Restart Time: Thursday, 02-May-2024 15:53:19 CEST Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 1 minute 46 seconds Server load: 0.06 0.07 0.17 Total accesses: 39 - Total Traffic: 29 kB - Total Duration: 22 CPU Usage: u.02 s.02 cu0 cs0 - .0377% CPU load .368 requests/sec - 280 B/second - 761 B/request - .564103 ms/request 2 requests currently being processed, 0 workers gracefully restarting, 3 idle workers ___RW........................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-0540400/5/5_ 0.000020.00.000.00 165.227.173.41http/1.1 1-0540410/9/9_ 0.010050.00.010.01 127.0.0.1http/1.1b3yard.com:8443GET / HTTP/1.0 2-0540420/10/10_ 0.000040.00.010.01 127.0.0.1http/1.1b3yard.com:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 3-0540430/8/8R 0.000040.00.010.01 127.0.0.1http/1.1b3yard.com:8080GET /debug/default/view?panel=config HTTP/1.0 4-0540440/7/7W 0.000050.00.000.00 127.0.0.1http/1.1b3yard.com:8080GET /server-status HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 4subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 299 seconds, (range: 299...299)index usage: 0%, cache usage: 0%total entries stored since starting: 4total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 7 misstotal removes since starting: 0 hit, 2 miss Apache/2.4.59 (Debian) Server at www.b3yard.com Port 80
Open service 172.67.213.225:443 · b3yard.com
2024-11-21 02:42
HTTP/1.1 200 OK Date: Thu, 21 Nov 2024 02:42:37 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close link: <https://b3yard.com/wp-json/>; rel="https://api.w.org/" x-frame-options: SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block CF-Cache-Status: DYNAMIC Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=6R9LDGodMvUBLhHCCpcOa9BH4kOqxT8tquoD%2FlxnSKtPmIlJFBUYoNV1%2F2FLj%2BU6aerF%2FeKSrYFUcUyijkLnOfYNdv%2FAQ0AvSHzAMYZAgDyJTkajJ6gJjSOv%2BPnN"}],"group":"cf-nel","max_age":604800} NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800} Server: cloudflare CF-RAY: 8e5d53d399aa8737-ORD alt-svc: h3=":443"; ma=86400 server-timing: cfL4;desc="?proto=TCP&rtt=99387&sent=5&recv=7&lost=0&retrans=0&sent_bytes=3089&recv_bytes=552&delivery_rate=43650&cwnd=33&unsent_bytes=0&cid=c4cef1e2db3dc73e&ts=700&x=0"
Open service 172.67.213.225:443 · b3yard.com
2024-11-18 23:49
HTTP/1.1 200 OK Date: Mon, 18 Nov 2024 23:49:40 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close link: <https://b3yard.com/wp-json/>; rel="https://api.w.org/" x-frame-options: SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block CF-Cache-Status: DYNAMIC Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=1ETll1OjewAhsSjIxPX7DXFplF8rnXb4cpwAUDOFye9RwBWyCcVTgN4gMl1%2FvUD4DL8sBG7P%2ByIIayM617sfdLP6lXjqxfFZWgOeb7OyuxA%2Ft2X1YO4UwukkNVyW"}],"group":"cf-nel","max_age":604800} NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800} Server: cloudflare CF-RAY: 8e4bdbbd0b3d9eb2-CDG alt-svc: h3=":443"; ma=86400 server-timing: cfL4;desc="?proto=TCP&rtt=12714&sent=5&recv=6&lost=0&retrans=0&sent_bytes=3089&recv_bytes=552&delivery_rate=339852&cwnd=253&unsent_bytes=0&cid=d36e4830b39236bb&ts=231&x=0"
Open service 172.67.213.225:443 · b3yard.com
2024-11-17 01:18
HTTP/1.1 200 OK Date: Sun, 17 Nov 2024 01:18:03 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close link: <https://b3yard.com/wp-json/>; rel="https://api.w.org/" x-frame-options: SAMEORIGIN x-content-type-options: nosniff x-xss-protection: 1; mode=block cf-cache-status: DYNAMIC vary: accept-encoding Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=4iKyyy%2FLNavIjK9thrD8m5fXa1RVxKWs2GZ0196BYrrrRe1YRnjdgqArkRxVE4KgIrAxdPP8SNX%2F4a%2BqVzb3QhTa0DuD4jo2ErHDT9JAMEO0JMXUYe2Mi%2Bo84TYi"}],"group":"cf-nel","max_age":604800} NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800} Server: cloudflare CF-RAY: 8e3be273def9d9d3-FRA alt-svc: h3=":443"; ma=86400 server-timing: cfL4;desc="?proto=TCP&rtt=858&sent=5&recv=6&lost=0&retrans=0&sent_bytes=3090&recv_bytes=552&delivery_rate=4670967&cwnd=247&unsent_bytes=0&cid=c9e3ad9664fa465e&ts=191&x=0"