The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb312d93930d2d93930d0c1251f6
Apache Status Apache Server Status for nagylak.ro (via 127.0.0.1) Server Version: Apache/2.4.52 (Ubuntu) OpenSSL/3.0.2 mod_fcgid/2.3.9 mpm-itk/2.4.7-04 Server MPM: prefork Server Built: 2022-09-30T04:09:50 Current Time: Wednesday, 21-Dec-2022 12:22:24 EET Restart Time: Monday, 19-Dec-2022 09:04:11 EET Parent Server Config. Generation: 292 Parent Server MPM Generation: 291 Server uptime: 2 days 3 hours 18 minutes 13 seconds Server load: 4.18 4.15 3.31 Total accesses: 567261 - Total Traffic: 39.3 GB - Total Duration: 448246363 CPU Usage: u350.01 s288.21 cu16744.4 cs68662.7 - 46.6% CPU load 3.07 requests/sec - 223.2 kB/second - 72.7 kB/request - 790.194 ms/request 8 requests currently being processed, 3 idle workers _CW.R..R_..RWW_.C............................................... ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-29138881990/119/47675_ 0.070139357162650.05.453920.62 127.0.0.1http/1.1t-challenge.eu:444GET /en/webquest/2/8/the-global-challenge-webquest HTTP/1.0 1-29139063531/4/47507C 0.00025338871091.30.013145.75 127.0.0.1http/1.1nagylak.ro:444GET /info.php HTTP/1.0 2-29138867110/137/45027W 0.0400324262440.09.733103.05 127.0.0.1http/1.1naturair.eu:444GET / HTTP/1.0 3-291-0/0/45541. 0.0035139330138620.00.003091.84 127.0.0.1http/1.1 4-29139014530/45/44668R 0.020449322504530.02.703059.48 127.0.0.1http/1.1rombird.ro:444GET /resized/uploaded---images/290/220/g:f/obs-b783d80e-57a0-40 5-291-0/0/43436. 0.0050988306517140.00.003176.58 127.0.0.1http/1.1 6-291-0/0/41564. 0.0049192306595440.00.002963.35 127.0.0.1http/1.1 7-29139016390/39/36714R 0.010362275018910.01.912508.67 127.0.0.1http/1.1rombird.ro:444GET /resized/uploaded---images/290/220/g:f/obs-dfca8fea-0048-46 8-29138869350/123/35879_ 0.0005276600030.07.002451.65 127.0.0.1http/1.1nagylak.ro:444GET /.DS_Store HTTP/1.0 9-291-0/0/32716. 0.004635228432510.00.002480.29 127.0.0.1http/1.1 10-291-0/0/29510. 0.00521044225451070.00.002050.60 127.0.0.1http/1.1sarkanykazan.ro:444GET /resized/uploaded---tiny---images---leirasokba/1200/800/puf 11-29138882490/118/30102R 0.0105207681050.05.712186.31 127.0.0.1http/1.1rombird.ro:444GET /images/favicon.ico?&ver=1671618143 HTTP/1.0 12-29139017680/45/24883W 0.0700170618640.02.791854.95 127.0.0.1http/1.1nagylak.ro:444GET /server-status HTTP/1.0 13-29139017740/38/11908W 0.0030125477430.02.29902.87 127.0.0.1http/1.1frbowling.ro:444GET /phpbb/viewtopic.php?f=7&t=23278 HTTP/1.0 14-29139017790/44/10124_ 0.0005107507790.02.23661.00 127.0.0.1http/1.1nagylak.ro:444GET / HTTP/1.0 15-291-0/0/10822. 0.002334116922930.00.00797.11 127.0.0.1http/1.1 16-29138021011/498/7117C 0.080155743979362.434.39504.32 127.0.0.1http/1.1t-challenge.eu:444GET /en/webquest/2/9/strategic-planning HTTP/1.0 17-291-0/0/4011. 0.00514544672150.00.00323.26 127.0.0.1http/1.1 18-291-0/0/2950. 0.00297169041205960.00.00194.56 127.0.0.1http/1.1 19-291-0/0/3933. 0.0026038737844030.00.00238.97 127.0.0.1http/1.1 20-291-0/0/2150. 0.00297684130483340.00.00138.12 127.0.0.1http/1.1transylvania-authentica.ro:444GET /lap/en/event/1671588355/33 HTTP/1.0 21-291-0/0/797. 0.00297695815777420.00.0086.92 127.0.0.1http/1.1transylvania-authentica.ro:444GET /lap/ro/evenimente/1671588355 HTTP/1.0 22-291-0/0/2004. 0.00297504131806850.00.00141.90 127.0.0.1http/1.1 23-291-0/0/1282. 0.00295805426449760.00.0047.00 127.0.0.1http/1.1 24-291-0/0/446. 0.00297534711813100.00.0030.60 127.0.0.1http/1.1 25-291-0/0/293. 0.00297677414167280.00.006.34 127.0.0.1http/1.1transylvania-authentica.ro:444GET /lap/hu/minden-esemeny/16/0 HTTP/1.0 26-291-0/0/202. 0.0029765795071300.00.0025.86 127.0.0.1http/1.1transylvania-authentica.ro:444GET /lap/hu/video-galeria/0/Tudatos-fogyasztas-1 HTTP/1.0 27-146-0/0/889. 0.00102863217016086220.00.0040.17 127.0.0.1http/1.1 28-146-0/0/443. 0.001028608115416380740.00.0019.48 127.0.0.1http/1.1 29-146-0/0/253. 0.001028724012939750.00.007.62 127.0.0.1http/1.1rombird.ro:444GET /ajaxsmarty.php?mod=blocks/maps/gmap-obs&id=43799 HTTP/1.0 30-146-0/0/91. 0.0010285843517620.00.002.26 127.0.0.1http/1.1csavargo.ro:444GET /static/font/Bookman/stylesheet.css HTTP/1.0 31-0-0/0/227. 0.00182163599225950.00.008.05 127.0.0.1http/1.1 32-0-0/0/377. 0.00181496385014208150.00.0015.13 127.0.0.1http/1.1 33-0-0/0/242. 0.0018213171958523380.00.007.52 127.0.0.1http/1.1 34-0-0/0/116. 0.001824022202463010.00.007.46 127.0.0.1http/1.1 35-0-0/0/111. 0.0018212874720020.00.005.13 127.0.0.1http/1.1csavargo.ro:444GET /images/bg.jpg HTTP/1.0 36-0-0/0/12. 0.001824031573306570.00.000.61 127.0.0.1http/1.1 37-0-0/0/113. 0.00181977376192900.00.003.75 127.0.0.1http/1.1 38-0-0/0/35. 0.0018231070021565370.00.000.75 127.0.0.1http/1.1 39-0-0/0/142. 0.0018184112407846980.00.003.19 127.0.0.1http/1.1 40-0-0/0/253. 0.00181576611145620.00.008.73 127.0.0.1http/1.1 41-0-0/0/47. 0.0018221370203209160.00.001.07 127.0.0.1http/1.1cstit.ro:444GET /hirek.php?id=-3219%27%20UNION%20ALL%20SELECT%20NULL%2CNULL 42-0-0/0/12. 0.001823953249310250.00.000.39 127.0.0.1http/1.1 43-0-0/0/7. 0.00184657334110240.00.000.11 127.0.0.1http/1.1 44-0-0/0/2. 0.0018468156750.00.000.01 127.0.0.1http/1.1 45-0-0/0/8. 0.001846674417140.00.000.14 127.0.0.1http/1.1 46-0-0/0/133. 0.0018433551851520.00.0010.87 127.0.0.1http/1.1 47-0-0/0/2. 0.00184680131810.00.000.00 127.0.0.1http/1.1 48-0-0/0/4. 0.001846662544155350.00.000.15 127.0.0.1http/1.1 49-0-0/0/6. 0.00184647182186580.00.000.49 127.0.0.1http/1.1 50-0-0/0/331. 0.0018373638725042220.00.0014.95 127.0.0.1http/1.1 51-0-0/0/16. 0.0018461425397690.00.000.54 127.0.0.1http/1.1konyvtar.hargitamegye.ro:444GET /resized/uploaded---images/158/118/317065531_55235730356718 52-0-0/0/58. 0.001845325983030.00.001.48 127.0.0.1http/1.1 53-0-0/0/8. 0.0018463721291330.00.000.22 127.0.0.1http/1.1 54-0-0/0/3. 0.00184679511230.00.000.03 127.0.0.1http/1.1rombird.ro:444GET /images/favicon.ico?&ver=1671433457 HTTP/1.0 55-0-0/0/8. 0.001846365042333800.00.000.46 127.0.0.1http/1.1