The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3139ac81c839ac81c88a8bb84d
Apache Status Apache Server Status for ftp.livegotoipo.com (via 27.254.96.168) Server Version: Apache/2.4.46 (Unix) OpenSSL/1.0.2u PHP/7.2.33 Server MPM: prefork Server Built: May 6 2022 15:05:21 Current Time: Wednesday, 26-Oct-2022 11:35:06 +07 Restart Time: Wednesday, 26-Oct-2022 11:35:03 +07 Parent Server Config. Generation: 479 Parent Server MPM Generation: 478 Server uptime: 3 seconds Server load: 1.49 1.41 1.28 Total accesses: 75 - Total Traffic: 499 kB - Total Duration: 10135 CPU Usage: u664.4 s1279.82 cu13004900 cs3128790 - 5.38e+8% CPU load 25 requests/sec - 166.3 kB/second - 6.7 kB/request - 135.133 ms/request 50 requests currently being processed, 0 idle workers RCCLCCWCRRCRCRCRCRWRCRRRCCCRCCCCCCCCWCLCCWCCCCCWCW Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-47810190/4/4R 0.040280.00.000.00 194.195.241.186http/1.1 1-47810201/2/2C 0.870119742.60.010.01 134.209.227.71http/1.1localhost:443GET /.env HTTP/1.1 2-47810231/2/2C 0.720116602.70.010.01 134.209.227.71http/1.1localhost:443GET /s/836313e26393e2435323e27323/_/;/META-INF/maven/com.atlass 3-47810351/6/6L 0.610011522.60.030.03 194.195.241.186http/1.1localhost:443GET /.DS_Store HTTP/1.1 4-47810421/14/14C 0.0600862.70.300.30 134.209.227.71http/1.1localhost:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 5-47810661/3/3C 0.03022242.60.030.03 134.209.227.71http/1.1localhost:443GET /telescope/requests HTTP/1.1 6-47810680/1/1W 0.550011220.00.000.00 172.70.218.44http/1.1www.bizproceed.com:80GET /?author=2 HTTP/1.0 7-47810741/2/2C 0.560111431.30.000.00 134.209.227.71http/1.1localhost:443GET /config.json HTTP/1.1 8-47810800/4/4R 0.0205120.00.010.01 194.195.241.186http/1.1 9-47810860/1/1R 0.010240.00.000.00 139.162.161.56http/1.1 10-47810911/1/1C 0.010122.60.000.00 134.209.227.71http/1.1localhost:443GET /info.php HTTP/1.1 11-47810930/4/4R 0.010140.00.000.00 194.195.241.186http/1.1 12-47810951/2/2C 0.020041.30.000.00 134.209.227.71http/1.1localhost:443GET /login.action HTTP/1.1 13-47811010/1/1R 0.010120.00.000.00 194.195.241.186http/1.1 14-47811081/2/2C 0.39007801.30.000.00 134.209.227.71http/1.1localhost:443GET /v2/_catalog HTTP/1.1 15-47811130/1/1R 0.010230.00.000.00 139.162.161.56http/1.1 16-47811201/1/1C 0.010252.60.000.00 134.209.227.71http/1.1localhost:443GET /.git/config HTTP/1.1 17-47811490/0/0R 0.000000.00.000.00 194.195.241.186http/1.1 18-47811580/0/0W 0.001000.00.000.00 162.158.159.130http/1.1www.dealaccounting.com:80POST /xmlrpc.php HTTP/1.0 19-47811610/1/1R 0.4304859700.00.000.00 172.105.91.134http/1.1 20-47811661/1/1C 0.4504438876.00.010.01 162.142.125.222http/1.1www.livegotoipo.com:443GET /favicon.ico HTTP/1.1 21-47811860/0/0W 0.000000.00.000.00 139.162.161.56http/1.1localhost:443GET /debug/default/view?panel=config HTTP/1.1 22-47811880/0/0R 0.000000.00.000.00 139.162.161.56http/1.1 23-47811890/0/0R 0.000000.00.000.00 139.162.161.56http/1.1 24-47811951/1/1C 0.010241.30.000.00 134.209.227.71http/1.1localhost:443GET /about HTTP/1.1 25-47812011/1/1C 0.010232.50.000.00 172.105.91.149http/1.1localhost:443GET /?rest_route=/wp/v2/users/ HTTP/1.1 26-47812041/1/1C 0.000232.60.000.00 172.105.91.149http/1.1localhost:443GET /.env HTTP/1.1 27-47812090/1/1R 0.010120.00.010.01 206.81.16.9http/1.1www.livegotoipo.com:443 28-47812161/1/1C 0.010012.70.000.00 172.105.91.149http/1.1localhost:443PUT /api/v2/cmdb/system/admin/admin HTTP/1.1 29-47812251/1/1C 0.000122.60.000.00 172.105.91.149http/1.1localhost:443GET /.git/config HTTP/1.1 30-47812311/1/1C 0.010242.60.000.00 172.105.91.149http/1.1localhost:443GET /telescope/requests HTTP/1.1 31-47812331/1/1C 0.010112.30.000.00 172.105.91.149http/1.1localhost:443GET / HTTP/1.1 32-47812411/1/1C 0.000112.70.000.00 172.105.91.149http/1.1localhost:443GET /debug/default/view?panel=config HTTP/1.1 33-47812471/1/1C 0.010132.60.000.00 172.105.91.149http/1.1localhost:443GET /info.php HTTP/1.1 34-47812551/1/1C 0.0105115.20.010.01 172.105.91.149http/1.1localhost:443GET /server-status HTTP/1.1 35-47812621/1/1C 0.010242.70.000.00 172.105.91.149http/1.1localhost:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 36-47812680/0/0W 0.000000.00.000.00 172.68.189.154http/1.1www.dealaccounting.com:80POST /wp-cron.php?doing_wp_cron=1666758905.85800790786743164062 37-47812771/1/1C 0.010242.70.000.00 139.162.161.56http/1.1localhost:443PUT /api/v2/cmdb/system/admin/admin HTTP/1.1 38-47812791/1/1C 0.020242.70.000.00 139.162.161.56http/1.1localhost:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 39-47812811/1/1C 0.010242.60.000.00 194.195.241.186http/1.1localhost:443GET /.env HTTP/1.1 40-47812891/1/1C 0.010242.70.000.00 194.195.241.186http/1.1localhost:443GET /s/836313e26393e2435323e27323/_/;/META-INF/maven/com.atlass 41-47812990/0/0W 0.000000.00.000.00 139.162.161.56http/1.1localhost:443GET / HTTP/1.1 42-47813071/1/1C 0.010122.50.000.00 139.162.161.56http/1.1localhost:443GET /?rest_route=/wp/v2/users/ HTTP/1.1 43-47813091/1/1C 0.010252.60.000.00 139.162.161.56http/1.1localhost:443GET /info.php HTTP/1.1 44-47813111/1/1C 0.000242.60.000.00 139.162.161.56http/1.1localhost:443GET /.env HTTP/1.1 45-47813201/1/1C 0.010132.50.000.00 194.195.241.186http/1.1localhost:443GET /?rest_route=/wp/v2/users/ HTTP/1.1 46-47813291/1/1C 0.010232.70.000.00 194.195.241.186http/1.1localhost:443PUT /api/v2/cmdb/system/admin/admin HTTP/1.1 47-47813371/1/1C 0.000252.60.000.00 139.162.161.56http/1.1localhost:443GET /.DS_Store HTTP/1.1 48-47813391/1/1C 0.000352.60.000.00 194.195.241.186http/1.1localhost:443GET /info.php HTTP/1.1 49-47813440/0/0W 0.000000.00.000.00 194.195.241.186http/1.1localhost:443GET /server-status HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 9subcaches: 32, indexes per subcache: 88ti
The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3139ac81c839ac81c8c637d92b
Apache Status Apache Server Status for ftp.livegotoipo.com (via 27.254.96.168) Server Version: Apache/2.4.46 (Unix) OpenSSL/1.0.2u PHP/7.2.33 Server MPM: prefork Server Built: May 6 2022 15:05:21 Current Time: Wednesday, 26-Oct-2022 11:34:59 +07 Restart Time: Wednesday, 26-Oct-2022 11:32:02 +07 Parent Server Config. Generation: 478 Parent Server MPM Generation: 477 Server uptime: 2 minutes 56 seconds Server load: 1.03 1.33 1.25 Total accesses: 469 - Total Traffic: 8.5 MB - Total Duration: 434090 CPU Usage: u759.62 s1302.84 cu13004800 cs3128760 - 9170000% CPU load 2.66 requests/sec - 49.4 kB/second - 18.5 kB/request - 925.565 ms/request 10 requests currently being processed, 0 idle workers RRRR.WRR.WRW...................................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-477314160/44/44R 17.420477423850.00.400.40 45.127.61.132http/1.1www.livegotoipo.com:80GET / HTTP/1.0 1-477314240/47/47R 14.5000762400.00.620.62 172.105.91.149http/1.1localhost:80GET / HTTP/1.0 2-477314400/51/51R 14.520449457870.00.540.54 162.142.125.222http/1.1www.livegotoipo.com:443GET / HTTP/1.1 3-477314500/49/49R 13.7301343730.02.862.86 172.105.91.134http/1.1localhost:80GET / HTTP/1.0 4-477-0/0/34. 0.00890303660.00.000.78 127.0.0.1http/1.1server1.chonlatee.com:80OPTIONS * HTTP/1.0 5-477314630/43/43W 10.8360370820.00.720.72 27.254.96.168http/1.1www.plastandtrans.com:443POST /wp-cron.php?doing_wp_cron=1666758892.72359800338745117187 6-477314700/39/39R 12.1900322740.00.440.44 162.142.125.222http/1.1www.livegotoipo.com:443 7-477314770/49/49R 12.540440434660.00.590.59 172.105.91.134http/1.1www.livegotoipo.com:443 8-477-0/0/28. 0.00840134100.00.000.78 127.0.0.1http/1.1server1.chonlatee.com:80OPTIONS * HTTP/1.0 9-477315930/23/27W 11.0300268050.00.130.20 162.142.125.222http/1.1www.livegotoipo.com:80GET / HTTP/1.0 10-477315140/33/33R 9.2500315650.00.450.45 206.81.16.9http/1.1www.livegotoipo.com:443 11-477316370/24/24W 8.0800203310.00.100.10 194.195.241.186http/1.1localhost:80GET /server-status HTTP/1.0 12-477-0/0/1. 0.00101010.00.000.00 127.0.0.1http/1.1server1.chonlatee.com:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 49subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 181 seconds, (range: 123...298)index usage: 1%, cache usage: 2%total entries stored since starting: 49total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 67 misstotal removes since starting: 0 hit, 0 miss