The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb311e6654871e665487dbf5932e
Apache Status Apache Server Status for cpass.udrohan.com Server Version: Apache/2.2.21 (Win32) mod_ssl/2.2.21 OpenSSL/1.0.0e PHP/5.3.8 mod_perl/2.0.4 Perl/v5.10.1 Server Built: Sep 10 2011 11:34:11 Current Time: Monday, 14-Nov-2022 02:25:27 Coordinated Universal Time Restart Time: Monday, 14-Nov-2022 01:08:17 Coordinated Universal Time Parent Server Generation: 0 Server uptime: 1 hour 17 minutes 10 seconds 11 requests currently being processed, 139 idle workers ________________________________________________________________ ________________________________________________________________ _______CCCCCCCWCW___C_.......................................... ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process PID Key: 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: _ , 7832 in state: _ 7832 in state: C , 7832 in state: C , 7832 in state: C 7832 in state: C , 7832 in state: C , 7832 in state: C 7832 in state: C , 7832 in state: W , 7832 in state: C 7832 in state: W , 7832 in state: _ , 7832 in state: _ 7832 in state: _ , 7832 in state: C , 7832 in state: _ To obtain a full report with current status information you need to use the ExtendedStatus On directive. SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current sessions: 0subcaches: 32, indexes per subcache: 133index usage: 0%, cache usage: 0%total sessions stored since starting: 1total sessions expired since starting: 1total (pre-expiry) sessions scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss