The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31902d5ce2902d5ce219032428
Apache Status Apache Server Status for mdl-cic.test.k8s.liip.ch (via 10.42.10.202) Server Version: Apache/2.4.56 (Debian) Server MPM: prefork Server Built: 2023-04-02T03:06:01 Current Time: Monday, 04-Sep-2023 08:25:17 UTC Restart Time: Monday, 04-Sep-2023 08:23:13 UTC Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 2 minutes 3 seconds Server load: 2.73 1.86 1.45 Total accesses: 62 - Total Traffic: 371 kB - Total Duration: 45083 CPU Usage: u5.1 s1.44 cu.02 cs.03 - 5.36% CPU load .504 requests/sec - 3088 B/second - 6.0 kB/request - 727.145 ms/request 3 requests currently being processed, 6 idle workers _K_W_K___....................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-0310/10/10_ 0.961283567900.00.020.02 127.0.0.1http/1.110.42.10.202:8080GET /admin/cron.php HTTP/1.1 1-0321/8/8K 0.1607714761.00.010.01 10.42.8.114http/1.110.42.10.202:8080GET /stats.php HTTP/1.1 2-0330/8/8_ 0.094706080.00.010.01 185.15.228.12http/1.110.42.10.202:8080GET /status.php HTTP/1.1 3-0340/6/6W 4.5400326520.00.180.18 10.42.5.80http/1.110.42.10.202:8080GET /server-status HTTP/1.1 4-0350/8/8_ 0.28012613310.00.040.04 10.42.6.78http/1.110.42.10.202:8080GET /.git/config HTTP/1.1 5-0362/10/10K 0.03401911.60.010.01 127.0.0.1http/1.110.42.10.202:8080GET /server-status/?auto HTTP/1.1 6-0370/9/9_ 0.2201289680.00.070.07 10.42.8.132http/1.110.42.10.202:8080GET /v2/_catalog HTTP/1.1 7-0420/3/3_ 0.13115010640.00.030.03 10.42.5.80http/1.110.42.10.202:8080GET /about HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot Apache/2.4.56 (Debian) Server at mdl-cic.test.k8s.liip.ch Port 8080
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31a52abf82a52abf82ff1c091f
Apache Status Apache Server Status for moodle.mdl-cic-updatetest (via 10.42.11.246) Server Version: Apache/2.4.56 (Debian) Server MPM: prefork Server Built: 2023-04-02T03:06:01 Current Time: Thursday, 06-Jul-2023 09:25:04 UTC Restart Time: Thursday, 06-Jul-2023 09:23:20 UTC Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 1 minute 44 seconds Server load: 0.92 1.38 0.90 Total accesses: 226 - Total Traffic: 31.5 MB - Total Duration: 139787 CPU Usage: u21.06 s7.23 cu6.12 cs1.49 - 34.5% CPU load 2.17 requests/sec - 309.8 kB/second - 142.6 kB/request - 618.527 ms/request 2 requests currently being processed, 9 idle workers _.K.W_____..___................................................. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-0510/19/24_ 1.031410296290.02.612.71 10.42.7.33http/1.110.42.11.246:8080GET /lib/ajax/service-nologin.php?info=6-method-calls&cachekey= 1-0-0/0/2. 0.0084015350.00.000.01 10.42.6.235http/1.110.42.11.246:8080GET /admin/index.php HTTP/1.1 2-0333/24/24K 4.1311231180634.25.425.42 10.42.7.33http/1.110.42.11.246:8080GET /v2/_catalog HTTP/1.1 3-0-0/0/9. 0.0066061840.00.000.13 127.0.0.1http/1.110.42.11.246:8080OPTIONS * HTTP/1.0 4-0356/21/21W 11.370068028122.112.0812.08 10.42.6.235http/1.110.42.11.246:8080GET /server-status HTTP/1.1 5-0360/10/10_ 1.291414536180.02.362.36 10.42.9.72http/1.110.42.11.246:8080GET /login/index.php HTTP/1.1 6-0370/9/9_ 1.251035830.00.220.22 127.0.0.1http/1.110.42.11.246:8080GET /server-status/?auto HTTP/1.1 7-0380/32/32_ 2.08166578270.02.572.57 185.15.228.25http/1.110.42.11.246:8080GET /status.php HTTP/1.1 8-0390/24/24_ 4.16679119020.00.530.53 185.15.228.25http/1.110.42.11.246:8080GET /status.php HTTP/1.1 9-0400/5/5_ 0.3965913040.00.100.10 185.15.228.25http/1.110.42.11.246:8080GET /status.php HTTP/1.1 10-0-0/0/22. 0.0055031960.00.002.65 127.0.0.1http/1.110.42.11.246:8080OPTIONS * HTTP/1.0 11-0-0/0/1. 0.0075000.00.000.00 127.0.0.1http/1.110.42.11.246:8080OPTIONS * HTTP/1.0 12-0430/27/27_ 2.0809567790.00.280.28 10.42.9.72http/1.110.42.11.246:8080GET / HTTP/1.1 13-0440/8/8_ 0.48912316420.00.020.02 10.42.6.235http/1.110.42.11.246:8080GET /login/index.php HTTP/1.1 14-0450/8/8_ 1.0711027460.02.372.37 127.0.0.1http/1.110.42.11.246:8080GET /server-status/?auto HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot Apache/2.4.56 (Debian) Server at moodle.mdl-cic-updatetest Port 80