The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31eedf37e2eedf37e21e2907aa
Apache Status Apache Server Status for image.dev.geo.de (via 10.41.69.126) Server Version: Apache/2.4.46 (Unix) Server MPM: event Server Built: May 11 2021 00:08:26 Current Time: Wednesday, 04-Jan-2023 07:30:18 Restart Time: Tuesday, 03-Jan-2023 05:11:23 Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 1 day 2 hours 18 minutes 55 seconds Server load: 0.71 0.81 1.25 Total accesses: 43198 - Total Traffic: 638.1 MB - Total Duration: 5633768 CPU Usage: u14.47 s14.48 cu0 cs0 - .0306% CPU load .456 requests/sec - 6.9 kB/second - 15.1 kB/request - 130.417 ms/request 2 requests currently being processed, 123 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 08no0yes025000 19no0yes025000 210no0yes025000 392no0yes025000 4120no1yes223000 Sum501 2123000 ________________________________________________________________ ______________________________________W____________________W_... ................................................................ ................................................................ ................................................................ ................................................................ ................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-080/181/181_ 2.8634749790.01.891.89 10.41.186.214http/1.1api-11freunde-dev.guj.digital:8GET /api/mt/desktop/v3/menu/p/club/ HTTP/1.1 0-080/180/180_ 2.8634057300.01.861.86 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/194/194_ 2.83923051250.01.531.53 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/183/183_ 2.837440672460.02.542.54 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/176/176_ 2.84924057390.00.850.85 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/181/181_ 2.86884086220.01.881.88 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/183/183_ 2.848940657260.01.931.93 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/201/201_ 2.865440708460.02.092.09 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/184/184_ 2.865140183880.01.861.86 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/179/179_ 2.86714039050.01.601.60 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/178/178_ 2.864440445210.00.840.84 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/165/165_ 2.86894043890.01.321.32 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/192/192_ 2.861040123240.01.361.36 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/189/189_ 2.85554046330.02.032.03 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/189/189_ 2.86904070330.02.242.24 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/179/179_ 2.85544083540.00.990.99 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/190/190_ 2.8654048670.01.491.49 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/189/189_ 2.8654040540.01.591.59 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/166/166_ 2.8644442753980.01.031.03 10.41.186.214http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/ HTTP/1.1 0-080/195/195_ 2.865540659870.01.861.86 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/185/185_ 2.84884507688610.02.982.98 10.41.186.214http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/?paidAuth=b6c40da75049c042d923caaf9 0-080/194/194_ 2.867440205810.02.522.52 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 0-080/209/209_ 2.86924051620.02.072.07 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/176/176_ 2.86544170470.01.621.62 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 0-080/183/183_ 2.849230334600.02.102.10 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 1-090/383/383_ 6.00840919190.05.685.68 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 1-090/394/394_ 5.972337175400.04.254.25 10.41.97.130http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/?paidAuth=b6c40da75049c042d923caaf9 1-090/411/411_ 6.003106968500.06.026.02 10.41.75.42http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/?paidAuth=b6c40da75049c042d923caaf9 1-090/393/393_ 6.001940152540.06.206.20 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 1-090/393/393_ 6.001150277930.06.946.94 10.41.114.184http/1.1default:8080GET /server-status?auto HTTP/1.1 1-090/420/420_ 6.001155204440.04.884.88 10.41.114.184http/1.1 1-090/411/411_ 5.9818414832450.06.336.33 10.41.191.13http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/?paidAuth=b6c40da75049c042d923caaf9 1-090/403/403_ 6.001640847250.05.365.36 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 1-090/384/384_ 5.993050188340.04.554.55 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 1-090/438/438_ 6.003105863510.06.486.48 10.41.75.42http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/?paidAuth=b6c40da75049c042d923caaf9 1-090/409/409_ 5.99645377230.08.568.56 10.41.41.38http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/?paidAuth=b6c40da75049c042d923caaf9 1-090/415/415_ 5.97520242610.04.924.92 10.41.114.184http/1.1 1-090/395/395_ 5.993741272790.04.994.99 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 1-090/398/398_ 6.0023826769130.04.894.89 10.41.41.38http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/news/?paidAuth=ed8a7bd8e987907bad52 1-090/399/399_ 6.00189111610820.05.985.98 10.41.84.171http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/?paidAuth=b6c40da75049c042d923caaf9 1-090/410/410_ 5.983050824380.04.904.90 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 1-090/413/413_ 6.00840327070.05.325.32 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 1-090/411/411_ 6.00641339090.05.115.11 10.41.122.215http/1.1default:8080GET /blueprint/servlet/healthcheck HTTP/1.1 1-090/407/407_ 6.001840398540.06.686.68 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 1-090/415/415_ 6.00190462186180.06.856.85 10.41.84.171http/1.1www.dev.stern.de:8080GET /api/onecore/desktop/v4/?paidAuth=b6c40da75049c042d923caaf9 1-090/405/405_ 6.00520813170.05.935.93 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 1-090/408/408_ 5.992330584740.05.785.78 10.41.122.215http/1.1default:8080GET /apache_ready HTTP/1.1 1-090/400/400_ 5.9823420719750.0