The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3185575ce785575ce7f61a4267
Apache Status Apache Server Status for hub.city17.cloud (via 10.0.2.100) Server Version: Apache/2.4.57 (Debian) PHP/8.2.11 Server MPM: prefork Server Built: 2023-04-13T03:26:51 Current Time: Thursday, 26-Oct-2023 23:27:16 UTC Restart Time: Tuesday, 24-Oct-2023 13:33:18 UTC Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 2 days 9 hours 53 minutes 58 seconds Server load: 2.43 3.91 4.00 Total accesses: 11077 - Total Traffic: 111.0 MB - Total Duration: 2897569 CPU Usage: u183.49 s24.47 cu11.32 cs2.22 - .106% CPU load .0531 requests/sec - 558 B/second - 10.3 kB/request - 261.584 ms/request 1 requests currently being processed, 9 idle workers _W_._._._....____............................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-0810/1061/1076_ 20.931195202890030.09.959.98 10.0.2.100http/1.110.0.2.100:80GET /favicon.ico HTTP/1.1 1-0577/1111/1111W 20.84002815898.12.582.58 10.0.2.100http/1.110.0.2.100:80GET /server-status HTTP/1.1 2-02540/965/1066_ 18.34260832552707030.03.804.17 10.0.2.100http/1.110.0.2.100:80PROPFIND /remote.php/dav/files/CITY17/Assets HTTP/1.1 3-0-0/0/136. 0.001624830323690.00.007.10 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 4-01780/985/1033_ 20.821372922850870.07.0610.88 10.0.2.100http/1.110.0.2.100:80GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1. 5-0-0/0/57. 0.001810510118190.00.003.52 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 6-0830/1092/1094_ 22.761195102852730.018.7018.70 10.0.2.100http/1.110.0.2.100:80GET /favicon.ico HTTP/1.1 7-0-0/0/35. 0.00181049086640.00.000.09 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 8-0740/1087/1088_ 20.36261732562910160.014.9214.92 10.0.2.100http/1.110.0.2.100:80PROPFIND /remote.php/dav/files/CITY17/Assets HTTP/1.1 9-0-0/0/41. 0.00181048063560.00.000.08 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 10-0-0/0/57. 0.001810470175990.00.000.15 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 11-0-0/0/36. 0.00181046047250.00.000.11 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 12-0-0/0/85. 0.001810450177630.00.000.21 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 13-0840/1041/1041_ 18.722617672788700.06.376.37 10.0.2.100http/1.110.0.2.100:80GET /ocs/v2.php/apps/user_status/api/v1/user_status?format=json 14-0850/1080/1080_ 20.47261432552813520.027.9427.94 10.0.2.100http/1.110.0.2.100:80PROPFIND /remote.php/dav/files/CITY17/Assets HTTP/1.1 15-0860/1024/1024_ 20.222611692807070.02.272.27 10.0.2.100http/1.110.0.2.100:80GET /ocs/v2.php/apps/notifications/api/v2/notifications?format= 16-01910/1007/1009_ 18.49261132582546650.01.921.92 10.0.2.100http/1.110.0.2.100:80PROPFIND /remote.php/dav/files/CITY17/Assets HTTP/1.1 17-0-0/0/1. 0.00205813000.00.000.00 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 18-0-0/0/1. 0.00205812000.00.000.00 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 19-0-0/0/1. 0.00205811000.00.000.00 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 20-0-0/0/1. 0.00205810000.00.000.00 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 21-0-0/0/1. 0.00205809000.00.000.00 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 22-0-0/0/1. 0.00205808000.00.000.00 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 23-0-0/0/1. 0.00205807000.00.000.00 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 24-0-0/0/1. 0.00205806000.00.000.00 ::1http/1.110.0.2.100:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot Apache/2.4.57 (Debian) Server at hub.city17.cloud Port 80
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3185575ce785575ce73268561c
Apache Status Apache Server Status for hub.city17.cloud (via 10.0.2.100) Server Version: Apache/2.4.57 (Debian) PHP/8.2.11 Server MPM: prefork Server Built: 2023-04-13T03:26:51 Current Time: Tuesday, 24-Oct-2023 13:33:52 UTC Restart Time: Tuesday, 24-Oct-2023 13:33:18 UTC Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 33 seconds Server load: 0.73 0.85 0.97 Total accesses: 12 - Total Traffic: 18 kB - Total Duration: 1600 CPU Usage: u.29 s.04 cu.22 cs1.07 - 4.91% CPU load .364 requests/sec - 558 B/second - 1536 B/request - 133.333 ms/request 1 requests currently being processed, 5 idle workers _W____.......................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-0560/2/2_ 0.23192412410.00.000.00 10.0.2.100http/1.110.0.2.100:80PROPFIND /remote.php/dav/files/CITY17/Assets HTTP/1.1 1-05710/10/10W 0.070035813.60.010.01 10.0.2.100http/1.110.0.2.100:80GET /server-status HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot Apache/2.4.57 (Debian) Server at hub.city17.cloud Port 80
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3185575ce785575ce7fed609a3
Apache Status Apache Server Status for hub.city17.cloud (via 10.0.2.100) Server Version: Apache/2.4.57 (Debian) PHP/8.2.8 Server MPM: prefork Server Built: 2023-04-13T03:26:51 Current Time: Sunday, 06-Aug-2023 04:46:23 UTC Restart Time: Sunday, 06-Aug-2023 04:45:05 UTC Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 1 minute 17 seconds Server load: 5.79 8.10 8.62 Total accesses: 22 - Total Traffic: 43 kB - Total Duration: 7428 CPU Usage: u.57 s.1 cu.03 cs.04 - .961% CPU load .286 requests/sec - 571 B/second - 2001 B/request - 337.636 ms/request 2 requests currently being processed, 6 idle workers _____WK_........................................................ ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-0300/2/2_ 0.1519012710.00.000.00 10.0.2.100http/1.110.0.2.100:80GET /data/htaccesstest.txt HTTP/1.1 1-0310/2/2_ 0.1619017610.00.000.00 10.0.2.100http/1.110.0.2.100:80GET /favicon.ico HTTP/1.1 2-0320/1/1_ 0.0020841690.00.000.00 10.0.2.100http/1.110.0.2.100:80GET /data/htaccesstest.txt HTTP/1.1 3-0330/1/1_ 0.081168513700.00.000.00 10.0.2.100http/1.110.0.2.100:80GET / HTTP/1.1 4-0340/2/2_ 0.0011020.00.000.00 10.0.2.100http/1.110.0.2.100:80GET /data/htaccesstest.txt HTTP/1.1 5-0637/7/7W 0.1500273812.10.010.01 10.0.2.100http/1.110.0.2.100:80GET /server-status HTTP/1.1 6-0647/7/7K 0.031011315.60.020.02 10.0.2.100http/1.110.0.2.100:80GET /data/htaccesstest.txt HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot Apache/2.4.57 (Debian) Server at hub.city17.cloud Port 80