The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb310b746ed30b746ed312011454
Apache Status Apache Server Status for erdelyinyaralas.ro (via 127.0.0.1) Server Version: Apache/2.4.52 (Ubuntu) OpenSSL/3.0.2 mod_fcgid/2.3.9 mpm-itk/2.4.7-04 Server MPM: prefork Server Built: 2023-03-01T22:43:55 Current Time: Wednesday, 12-Jul-2023 10:24:58 EEST Restart Time: Wednesday, 12-Jul-2023 10:16:25 EEST Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 8 minutes 33 seconds Server load: 2.41 2.55 3.74 Total accesses: 6128 - Total Traffic: 142.6 MB - Total Duration: 3643316 CPU Usage: u1.09 s2.12 cu130.91 cs345.62 - 93.5% CPU load 11.9 requests/sec - 284.7 kB/second - 23.8 kB/request - 594.536 ms/request 3 requests currently being processed, 7 idle workers __C_W.R..__......._..._......................................... ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-013136210/117/501_ 0.060681321120.02.1613.04 127.0.0.1http/1.1payment.erdelyivendeghazak.ro:4GET /telescope/requests HTTP/1.0 1-013127770/119/358_ 0.00041446890.02.038.65 127.0.0.1http/1.1erdelyiszallasok.ro:444GET /.DS_Store HTTP/1.0 2-013225461/38/422C 0.010101619813.30.3510.06 127.0.0.1http/1.1cjphr.ro:444GET /static2012/js/tinymce/tiny_mce_2014/plugins/tinybrowser/cs 3-013130780/112/358_ 0.00051646950.01.869.08 127.0.0.1http/1.1erdelyiszallasok.ro:444GET /_all_dbs HTTP/1.0 4-013225920/35/282W 0.01001310030.00.398.64 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /server-status HTTP/1.0 5-0-0/0/327. 0.002251644980.00.009.52 127.0.0.1http/1.1 6-013137650/97/352R 0.00041558570.02.159.54 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /_all_dbs HTTP/1.0 7-0-0/0/312. 0.002491448650.00.006.63 127.0.0.1http/1.1 8-0-0/0/368. 0.002591202110.00.008.56 127.0.0.1http/1.1 9-013228160/34/346_ 0.0601151777450.00.518.00 127.0.0.1http/1.1novakcukraszda.ro:444GET /hu HTTP/1.0 10-013158870/86/260_ 0.030401274800.01.674.87 127.0.0.1http/1.1harplast.ro:444GET /resized/uploaded---images/500/500/f/szopos_zsolt.jpg HTTP/ 11-0-0/0/175. 0.0026882788080.00.003.32 127.0.0.1http/1.1 12-0-0/0/177. 0.00215647170.00.003.17 127.0.0.1http/1.1 13-0-0/0/119. 0.00989886330.00.002.49 127.0.0.1http/1.1dilussofinefurniture.ca:444GET /v2/_catalog HTTP/1.0 14-0-0/0/94. 0.0078280291007090.00.002.79 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /erdelyi-vendeghaz-nagylak-2/erdelyi-utazas-hasznos-tanacso 15-0-0/0/123. 0.001017749170.00.002.61 127.0.0.1http/1.1 16-0-0/0/298. 0.009313767760.00.005.74 127.0.0.1http/1.1 17-0-0/0/145. 0.00669984370.00.002.20 127.0.0.1http/1.1 18-013138750/91/105_ 0.110128977960.01.641.72 127.0.0.1http/1.1cjphr.ro:444GET /static2012/js/tinymce/tiny_mce_2014/plugins/tinybrowser/ti 19-0-0/0/40. 0.006436617470.00.001.34 127.0.0.1http/1.1 20-0-0/0/19. 0.00735778590.00.000.39 127.0.0.1http/1.1 21-0-0/0/17. 0.00908798120.00.000.12 127.0.0.1http/1.1edenkert.ro:444GET /server-status HTTP/1.0 22-013138900/97/99_ 0.00051086890.02.442.56 127.0.0.1http/1.1erdelyiszallasok.ro:444GET /.DS_Store HTTP/1.0 23-0-0/0/11. 0.00996636620.00.000.09 127.0.0.1http/1.1harplast.ro:444GET /images/bk.jpg HTTP/1.1 24-0-0/0/145. 0.0072391013400.00.001.85 127.0.0.1http/1.1 25-0-0/0/23. 0.006765545550.00.000.18 127.0.0.1http/1.1 26-0-0/0/32. 0.0065191688400.00.001.16 127.0.0.1http/1.1csikszentimre.ro:444GET /ro/articles/22/9/agricol-si-funciar HTTP/1.0 27-0-0/0/14. 0.0095834518320.00.000.48 127.0.0.1http/1.1 28-0-0/0/15. 0.008575576540.00.000.34 127.0.0.1http/1.1 29-0-0/0/33. 0.008974450120.00.001.46 127.0.0.1http/1.1payment.erdelyivendeghazak.ro:4GET /production.json HTTP/1.0 30-0-0/0/17. 0.0069152604400.00.000.28 127.0.0.1http/1.1 31-0-0/0/13. 0.008333602130.00.000.11 127.0.0.1http/1.1harplast.ro:444GET /resized/uploaded---tiny---images---auto---product---120--- 32-0-0/0/14. 0.007740702750.00.000.19 127.0.0.1http/1.1 33-0-0/0/54. 0.007648135370.00.001.24 127.0.0.1http/1.1 34-0-0/0/22. 0.007071537330.00.000.62 127.0.0.1http/1.1 35-0-0/0/31. 0.00635743980.00.001.26 127.0.0.1http/1.1mohos.ro:444GET /class.api.php HTTP/1.0 36-0-0/0/49. 0.008135115030.00.001.35 127.0.0.1http/1.1 37-0-0/0/36. 0.00865369130.00.000.25 127.0.0.1http/1.1 38-0-0/0/34. 0.006145672200.00.000.79 127.0.0.1http/1.1 39-0-0/0/18. 0.006234679130.00.000.67 127.0.0.1http/1.1 40-0-0/0/78. 0.001429162330.00.001.48 127.0.0.1http/1.1 41-0-0/0/12. 0.009622521500.00.000.15 127.0.0.1http/1.1harplast.ro:444GET /produse HTTP/1.1 42-0-0/0/18. 0.00887040130.00.000.43 127.0.0.1http/1.1payment.erdelyivendeghazak.ro:4GET /Dockerfile HTTP/1.0 43-0-0/0/21. 0.00744039840.00.000.54 127.0.0.1http/1.1harplast.ro:444POST /ro/products/addview/29 HTTP/1.1 44-0-0/0/15. 0.008716519550.00.000.34 127.0.0.1http/1.1erdelyivasarter.ro:444GET / HTTP/1.0 45-0-0/0/19. 0.00752227740.00.000.27 127.0.0.1http/1.1bellavita.marien.ro:444GET /hargita/guestbook.php?id=e25P746y57m2j2I8&lang=hu HTTP/1.0 46-0-0/0/67. 0.002310138770.00.001.32 127.0.0.1http/1.1takaritas.ro:444GET /static2012/fonts/lora/fonts/Lora-Regular.woff HTTP/1.0 47-0-0/0/1. 0.001021513010.00.000.02 127.0.0.1http/1.1 48-0-0/0/16. 0.00801118640.00.000.27 127.0.0.1http/1.1edenkert.ro:444GET / HTTP/1.0 49-0-0/0/4. 0.0010071360.00.000.01 127.0.0.1http/1.1drlaser.eu:444GET / HTTP/1.0 50-0-0/0/6. 0.0097793860.00.000.27 127.0.0.1http/1.1 51-0-0/0/13. 0.00823625420.00.000.17 127.0.0.1http/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot mod_fcgid status: Total FastCGI processes: 0 SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 2272subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 152 seconds, (range: 112...184)index usage: 80%, cache usage: 99%
The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3188f416bc88f416bc8ba17048
Apache Status Apache Server Status for mail.erdelyinyaralas.ro (via 127.0.0.1) Server Version: Apache/2.4.52 (Ubuntu) OpenSSL/3.0.2 mod_fcgid/2.3.9 mpm-itk/2.4.7-04 Server MPM: prefork Server Built: 2023-03-01T22:43:55 Current Time: Wednesday, 12-Jul-2023 10:24:51 EEST Restart Time: Wednesday, 12-Jul-2023 10:16:25 EEST Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 8 minutes 26 seconds Server load: 2.27 2.52 3.74 Total accesses: 6015 - Total Traffic: 141.8 MB - Total Duration: 3636428 CPU Usage: u1 s2.09 cu130.91 cs345.62 - 94.8% CPU load 11.9 requests/sec - 287.1 kB/second - 24.1 kB/request - 604.56 ms/request 2 requests currently being processed, 8 idle workers W__W_._..__......._..._......................................... ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-013136210/105/489W 0.03001315340.02.1112.99 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /server-status HTTP/1.0 1-013127770/108/347_ 0.0101021429480.01.968.57 127.0.0.1http/1.1margareta.panzio.ro:444GET /guestbook.php?id=z2kp643p04I9FjR6&lang=en HTTP/1.0 2-013225460/26/410_ 0.01051616620.00.3010.02 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 3-013130780/100/346W 0.02001642530.01.829.04 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /.git/config HTTP/1.0 4-013225920/24/271_ 0.01041304910.00.358.60 127.0.0.1http/1.1falco.ro:444GET /https://falco.ro/ HTTP/1.0 5-0-0/0/327. 0.001451644980.00.009.52 127.0.0.1http/1.1 6-013137650/86/341_ 0.01051553610.02.059.44 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /.env HTTP/1.0 7-0-0/0/312. 0.001691448650.00.006.63 127.0.0.1http/1.1 8-0-0/0/368. 0.001791202110.00.008.56 127.0.0.1http/1.1 9-013228160/24/336_ 0.020361763530.00.467.95 127.0.0.1http/1.1falco.ro:444GET /Products/Equipments/ HTTP/1.0 10-013158870/74/248_ 0.010251271030.01.384.59 127.0.0.1http/1.1rombird.ro:444GET /resized/uploaded---tiny---images---uj1---/965/580/ban1.jpg 11-0-0/0/175. 0.0018882788080.00.003.32 127.0.0.1http/1.1 12-0-0/0/177. 0.00135647170.00.003.17 127.0.0.1http/1.1 13-0-0/0/119. 0.00919886330.00.002.49 127.0.0.1http/1.1dilussofinefurniture.ca:444GET /v2/_catalog HTTP/1.0 14-0-0/0/94. 0.0070280291007090.00.002.79 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /erdelyi-vendeghaz-nagylak-2/erdelyi-utazas-hasznos-tanacso 15-0-0/0/123. 0.00947749170.00.002.61 127.0.0.1http/1.1 16-0-0/0/298. 0.008613767760.00.005.74 127.0.0.1http/1.1 17-0-0/0/145. 0.00589984370.00.002.20 127.0.0.1http/1.1 18-013138750/80/94_ 0.03035968730.01.561.64 127.0.0.1http/1.1falco.ro:444GET /info HTTP/1.0 19-0-0/0/40. 0.005636617470.00.001.34 127.0.0.1http/1.1 20-0-0/0/19. 0.00655778590.00.000.39 127.0.0.1http/1.1 21-0-0/0/17. 0.00838798120.00.000.12 127.0.0.1http/1.1edenkert.ro:444GET /server-status HTTP/1.0 22-013138900/86/88_ 0.01041085810.02.422.54 127.0.0.1http/1.1erdelyinyaralas.ro:444GET /.DS_Store HTTP/1.0 23-0-0/0/11. 0.00926636620.00.000.09 127.0.0.1http/1.1harplast.ro:444GET /images/bk.jpg HTTP/1.1 24-0-0/0/145. 0.0064391013400.00.001.85 127.0.0.1http/1.1 25-0-0/0/23. 0.005965545550.00.000.18 127.0.0.1http/1.1 26-0-0/0/32. 0.0057191688400.00.001.16 127.0.0.1http/1.1csikszentimre.ro:444GET /ro/articles/22/9/agricol-si-funciar HTTP/1.0 27-0-0/0/14. 0.0088834518320.00.000.48 127.0.0.1http/1.1 28-0-0/0/15. 0.007875576540.00.000.34 127.0.0.1http/1.1 29-0-0/0/33. 0.008274450120.00.001.46 127.0.0.1http/1.1payment.erdelyivendeghazak.ro:4GET /production.json HTTP/1.0 30-0-0/0/17. 0.0061152604400.00.000.28 127.0.0.1http/1.1 31-0-0/0/13. 0.007633602130.00.000.11 127.0.0.1http/1.1harplast.ro:444GET /resized/uploaded---tiny---images---auto---product---120--- 32-0-0/0/14. 0.006940702750.00.000.19 127.0.0.1http/1.1 33-0-0/0/54. 0.006848135370.00.001.24 127.0.0.1http/1.1 34-0-0/0/22. 0.006271537330.00.000.62 127.0.0.1http/1.1 35-0-0/0/31. 0.00555743980.00.001.26 127.0.0.1http/1.1mohos.ro:444GET /class.api.php HTTP/1.0 36-0-0/0/49. 0.007335115030.00.001.35 127.0.0.1http/1.1 37-0-0/0/36. 0.00795369130.00.000.25 127.0.0.1http/1.1 38-0-0/0/34. 0.005345672200.00.000.79 127.0.0.1http/1.1 39-0-0/0/18. 0.005434679130.00.000.67 127.0.0.1http/1.1 40-0-0/0/78. 0.00629162330.00.001.48 127.0.0.1http/1.1 41-0-0/0/12. 0.008922521500.00.000.15 127.0.0.1http/1.1harplast.ro:444GET /produse HTTP/1.1 42-0-0/0/18. 0.00817040130.00.000.43 127.0.0.1http/1.1payment.erdelyivendeghazak.ro:4GET /Dockerfile HTTP/1.0 43-0-0/0/21. 0.00664039840.00.000.54 127.0.0.1http/1.1harplast.ro:444POST /ro/products/addview/29 HTTP/1.1 44-0-0/0/15. 0.008016519550.00.000.34 127.0.0.1http/1.1erdelyivasarter.ro:444GET / HTTP/1.0 45-0-0/0/19. 0.00672227740.00.000.27 127.0.0.1http/1.1bellavita.marien.ro:444GET /hargita/guestbook.php?id=e25P746y57m2j2I8&lang=hu HTTP/1.0 46-0-0/0/67. 0.001510138770.00.001.32 127.0.0.1http/1.1takaritas.ro:444GET /static2012/fonts/lora/fonts/Lora-Regular.woff HTTP/1.0 47-0-0/0/1. 0.00951513010.00.000.02 127.0.0.1http/1.1 48-0-0/0/16. 0.00721118640.00.000.27 127.0.0.1http/1.1edenkert.ro:444GET / HTTP/1.0 49-0-0/0/4. 0.009371360.00.000.01 127.0.0.1http/1.1drlaser.eu:444GET / HTTP/1.0 50-0-0/0/6. 0.0090793860.00.000.27 127.0.0.1http/1.1 51-0-0/0/13. 0.00753625420.00.000.17 127.0.0.1http/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot mod_fcgid status: Total FastCGI processes: 0 SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 2272subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 153 seconds, (range: 107...176)index usage: 80%, cache usage: 99%total entries stored sinc