The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31d09ad080d09ad0808e8660e7
Apache Status Apache Server Status for insar.io (via 127.0.0.1) Server Version: Apache/2.4.54 (Debian) mod_fcgid/2.3.9 Server MPM: prefork Server Built: 2022-06-09T04:26:43 Current Time: Friday, 08-Dec-2023 00:11:40 EST Restart Time: Tuesday, 28-Nov-2023 02:52:16 EST Parent Server Config. Generation: 21 Parent Server MPM Generation: 20 Server uptime: 9 days 21 hours 19 minutes 24 seconds Server load: 0.00 0.00 0.00 Total accesses: 83113 - Total Traffic: 428.5 MB - Total Duration: 7047721 CPU Usage: u11.49 s14.73 cu1688.55 cs183.15 - .222% CPU load .0973 requests/sec - 525 B/second - 5.3 kB/request - 84.7969 ms/request 1 requests currently being processed, 6 idle workers ____W__......................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-20775820/7/11629_ 0.080110305670.00.0574.68 127.0.0.1http/1.1annanazarova.com:8080GET /server-status HTTP/1.0 1-20775830/7/11635_ 0.62009669080.00.0249.95 127.0.0.1http/1.1annanazarova.com:8080GET /debug/default/view?panel=config HTTP/1.0 2-20775840/7/11629_ 1.57009229140.00.0344.57 127.0.0.1http/1.1annanazarova.com:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 3-20775850/7/11625_ 0.17009246050.00.0349.67 127.0.0.1http/1.1annanazarova.com:8080GET /login.action HTTP/1.0 4-20775860/6/11622W 0.20009952020.00.0150.17 127.0.0.1http/1.1annanazarova.com:8080GET /server-status HTTP/1.0 5-20775870/6/11612_ 0.190010029750.00.0172.05 127.0.0.1http/1.1annanazarova.com:8080GET /v2/_catalog HTTP/1.0 6-20775920/6/10635_ 0.69009026880.00.0157.21 127.0.0.1http/1.1annanazarova.com:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 7-18-0/0/1857. 0.00699122193730.00.009.26 127.0.0.1http/1.1reshetnikov.com:8081POST /xmlrpc.php HTTP/1.0 8-6-0/0/789. 0.005190945667000.00.0020.58 127.0.0.1http/1.1annanazarova.com:8080GET /blog/category/england/feed/ HTTP/1.0 9-6-0/0/80. 0.0051909421157850.00.000.40 127.0.0.1http/1.1annanazarova.com:8080GET /blog/category/wildlife/page/2/ HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot mod_fcgid status: Total FastCGI processes: 0 Apache/2.4.54 (Debian) Server at insar.io Port 80
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31d09ad080d09ad080f440d839
Apache Status Apache Server Status for insar.io (via 127.0.0.1) Server Version: Apache/2.4.54 (Debian) mod_fcgid/2.3.9 Server MPM: prefork Server Built: 2022-06-09T04:26:43 Current Time: Friday, 08-Dec-2023 00:11:40 EST Restart Time: Tuesday, 28-Nov-2023 02:52:16 EST Parent Server Config. Generation: 21 Parent Server MPM Generation: 20 Server uptime: 9 days 21 hours 19 minutes 23 seconds Server load: 0.00 0.00 0.00 Total accesses: 83109 - Total Traffic: 428.5 MB - Total Duration: 7047717 CPU Usage: u11.49 s14.73 cu1688.55 cs183.15 - .222% CPU load .0973 requests/sec - 525 B/second - 5.3 kB/request - 84.8009 ms/request 1 requests currently being processed, 6 idle workers W______......................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-20775820/6/11628W 0.080010305640.00.0474.68 127.0.0.1http/1.1annanazarova.com:8080GET /server-status HTTP/1.0 1-20775830/7/11635_ 0.62009669080.00.0249.95 127.0.0.1http/1.1annanazarova.com:8080GET /debug/default/view?panel=config HTTP/1.0 2-20775840/7/11629_ 1.57009229140.00.0344.57 127.0.0.1http/1.1annanazarova.com:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 3-20775850/6/11624_ 0.17009246050.00.0349.67 127.0.0.1http/1.1annanazarova.com:8080GET /v2/_catalog HTTP/1.0 4-20775860/6/11622_ 0.20009952020.00.0150.17 127.0.0.1http/1.1annanazarova.com:8080GET /about HTTP/1.0 5-20775870/5/11611_ 0.190010029740.00.0172.05 127.0.0.1http/1.1annanazarova.com:8080GET /debug/default/view?panel=config HTTP/1.0 6-20775920/5/10634_ 0.69009026870.00.0157.21 127.0.0.1http/1.1annanazarova.com:8080GET /.vscode/sftp.json HTTP/1.0 7-18-0/0/1857. 0.00698122193730.00.009.26 127.0.0.1http/1.1reshetnikov.com:8081POST /xmlrpc.php HTTP/1.0 8-6-0/0/789. 0.005190935667000.00.0020.58 127.0.0.1http/1.1annanazarova.com:8080GET /blog/category/england/feed/ HTTP/1.0 9-6-0/0/80. 0.0051909321157850.00.000.40 127.0.0.1http/1.1annanazarova.com:8080GET /blog/category/wildlife/page/2/ HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot mod_fcgid status: Total FastCGI processes: 0 Apache/2.4.54 (Debian) Server at insar.io Port 80