The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31198ffff2198ffff271ebbcde
Apache Status Apache Server Status for order.commejaime.ch (via 10.201.0.39) Server Version: Apache/2.4.59 (Debian) OpenSSL/3.0.11 Server MPM: event Server Built: 2024-04-05T12:02:26 Current Time: Tuesday, 11-Mar-2025 10:10:47 CET Restart Time: Monday, 10-Mar-2025 14:48:32 CET Parent Server Config. Generation: 5 Parent Server MPM Generation: 4 Server uptime: 19 hours 22 minutes 14 seconds Server load: 0.03 0.09 0.11 Total accesses: 17215 - Total Traffic: 41.9 MB - Total Duration: 7613 CPU Usage: u3.38 s2.41 cu7.79 cs6.25 - .0284% CPU load .247 requests/sec - 629 B/second - 2551 B/request - .442231 ms/request 1 requests currently being processed, 0 workers gracefully restarting, 49 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusygracefulidlewritingkeep-aliveclosing 02117075no0yes1024000 12117076no1yes0025000 Sum201 1049000 ______R___________________________________________.............. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-421170750/22/343_ 1.302701390.00.040.86 172.71.95.71h2r.commejaime.be:443GET ///payment-direct-bcmc?hash=79397fe834 HTTP/2.0 0-421170750/23/327_ 1.312401370.00.090.81 35.87.126.83h2r.regimebox.fr:443GET / HTTP/2.0 0-421170750/29/334_ 1.311901330.00.130.87 35.87.126.83h2r.regimebox.fr:443GET /build/0.1e27c7fb.js HTTP/2.0 0-421170750/22/319_ 1.17002470.00.040.77 172.70.248.99h2default.:443GET /.git/config HTTP/2.0 0-421170750/29/339_ 1.334801400.00.060.80 172.71.95.72h2r.commejaime.be:443GET ///payment-direct-bcmc?hash=e42b2a6700 HTTP/2.0 0-421170750/19/322_ 1.34001300.00.040.73 104.23.190.124h2default.:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-421170750/26/320R 1.174901540.00.100.79 172.70.114.147h2default.:443[1/0] schedule: stream 1, GET /server-status 0-421170750/20/337_ 1.211901420.00.040.77 172.70.243.74h2default.:443GET /s/13e22333e21323e2430313/_/;/META-INF/maven/com.atlassian. 0-421170750/18/319_ 1.14001350.00.040.74 35.87.126.83h2r.regimebox.fr:443[6/6] done 0-421170750/22/329_ 1.34101500.00.050.76 104.23.190.50h2default.:443GET /about HTTP/2.0 0-421170750/30/336_ 1.333202080.00.120.87 172.71.155.59h2default.:443GET / HTTP/2.0 0-421170750/23/322_ 1.184901390.00.060.76 172.71.246.155h2default.:443GET /s/13e24363e21323e2430313/_/;/META-INF/maven/com.atlassian. 0-421170750/22/337_ 1.334601420.00.070.89 172.70.130.243h2default.:443GET /blog/.git/config HTTP/2.0 0-421170750/24/331_ 1.262701360.00.130.85 172.71.95.72h2r.commejaime.be:443GET ///payment-direct-bcmc?hash=5b1389ec7f HTTP/2.0 0-421170750/24/337_ 1.284101440.00.070.86 172.71.154.187h2default.:443GET /http%3A/httpd.apache.org/docs/2.4/mod/mod_userdir.html HTT 0-421170750/28/339_ 1.274301550.00.150.91 172.71.95.71h2r.commejaime.be:443GET ///payment-direct-bcmc?hash=5b1389ec7f HTTP/2.0 0-421170750/25/330_ 1.333201360.00.070.82 172.71.155.59h2default.:443GET / HTTP/2.0 0-421170750/24/311_ 1.154101300.00.040.73 162.158.94.23h2default.:443GET /.DS_Store HTTP/2.0 0-421170750/20/330_ 1.233261440.00.060.79 172.71.172.213h2default.:443GET /telescope/requests HTTP/2.0 0-421170750/30/326_ 1.293201390.00.130.80 35.87.126.83h2r.regimebox.fr:443GET /build/1.d0cb8f43.js HTTP/2.0 0-421170750/20/325_ 1.184301690.00.040.75 172.68.194.161h2default.:443GET /info.php HTTP/2.0 0-421170750/21/330_ 1.212701360.00.030.77 172.71.246.83h2default.:443GET /.git/config HTTP/2.0 0-421170750/24/326_ 1.202701360.00.090.84 172.70.240.43h2default.:443GET /login.action HTTP/2.0 0-421170750/27/343_ 1.342401370.00.090.85 108.162.216.175h2default.:443GET /home/.git/config HTTP/2.0 0-421170750/18/319_ 1.184601350.00.030.73 172.71.172.201h2default.:443GET /.vscode/sftp.json HTTP/2.0 1-421170760/43/358_ 1.64001530.00.100.84 172.70.110.119h2default.:443GET /debug/default/view?panel=config HTTP/2.0 1-421170760/41/369_ 1.61101640.00.160.92 162.158.155.26h2default.:443GET / HTTP/2.0 1-421170760/35/352_ 1.65001590.00.080.82 162.158.159.151h2default.:443GET /debug/default/view?panel=config HTTP/2.0 1-421170760/41/344_ 1.56001420.00.160.85 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/42/357_ 1.65001540.00.080.84 162.158.62.111h2default.:443GET /v2/_catalog HTTP/2.0 1-421170760/44/377_ 1.67001570.00.130.91 104.23.187.63h2default.:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-421170760/45/360_ 1.56001750.00.160.93 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/41/375_ 1.54001660.00.160.95 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/44/367_ 1.63001570.00.180.96 162.158.158.141h2default.:443GET /server HTTP/2.0 1-421170760/39/354_ 1.67001520.00.090.81 172.70.230.196h2default.:443GET /server-status HTTP/2.0 1-421170760/38/346_ 1.60101510.00.090.81 162.158.111.123h2default.:443GET / HTTP/2.0 1-421170760/43/348_ 1.64101520.00.160.94 172.71.246.155h2default.:443GET / HTTP/2.0 1-421170760/41/344_ 1.59101490.00.130.82 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/38/360_ 1.50101510.00.080.82 162.158.87.211h2default.:443GET /.DS_Store HTTP/2.0 1-421170760/46/360_ 1.64101500.00.100.83 172.70.251.111h2default.:443GET / HTTP/2.0 1-421170760/40/350_ 1.64101480.00.090.86 162.158.63.33h2default.:443GET /.vscode/sftp.json HTTP/2.0 1-421170760/45/358_ 1.65001550.00.090.89 172.70.111.65h2default.:443GET /v2/_catalog HTTP/2.0 1-421170760/38/358_ 1.59101510.00.080.90 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/46/370_ 1.59111570.00.130.88 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/43/360_ 1.59101700.00.100.86 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/45/360_ 1.64101550.00.090.84 172.70.114.205h2default.:443GET /.vscode/sftp.json HTTP/2.0 1-421170760/39/365_ 1.63101590.00.090.86 162.158.159.89h2default.:443GET /server HTTP/2.0 1-421170760/46/365_ 1.64101540.00.180.92 172.70.110.206h2default.:443GET /about HTTP/2.0 1-421170760/37/364_ 1.63001610.00.080.85 104.23.187.194h2default.:443GET /actuator/env HTTP/2.0 1-421170760/44/363_ 1.59001530.00.090.83 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31198ffff2198ffff275b4eece
Apache Status Apache Server Status for order.commejaime.ch (via 10.201.0.39) Server Version: Apache/2.4.59 (Debian) OpenSSL/3.0.11 Server MPM: event Server Built: 2024-04-05T12:02:26 Current Time: Tuesday, 11-Mar-2025 10:10:46 CET Restart Time: Monday, 10-Mar-2025 14:48:32 CET Parent Server Config. Generation: 5 Parent Server MPM Generation: 4 Server uptime: 19 hours 22 minutes 14 seconds Server load: 0.03 0.09 0.11 Total accesses: 17214 - Total Traffic: 41.9 MB - Total Duration: 7613 CPU Usage: u3.38 s2.41 cu7.79 cs6.25 - .0284% CPU load .247 requests/sec - 629 B/second - 2551 B/request - .442256 ms/request 1 requests currently being processed, 0 workers gracefully restarting, 49 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusygracefulidlewritingkeep-aliveclosing 02117075no0yes0025000 12117076no1yes1024000 Sum201 1049000 __________________________________R_______________.............. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-421170750/22/343_ 1.302701390.00.040.86 172.71.95.71h2r.commejaime.be:443GET ///payment-direct-bcmc?hash=79397fe834 HTTP/2.0 0-421170750/23/327_ 1.312401370.00.090.81 35.87.126.83h2r.regimebox.fr:443GET / HTTP/2.0 0-421170750/29/334_ 1.311901330.00.130.87 35.87.126.83h2r.regimebox.fr:443GET /build/0.1e27c7fb.js HTTP/2.0 0-421170750/22/319_ 1.17002470.00.040.77 172.70.248.99h2default.:443GET /.git/config HTTP/2.0 0-421170750/29/339_ 1.334801400.00.060.80 172.71.95.72h2r.commejaime.be:443GET ///payment-direct-bcmc?hash=e42b2a6700 HTTP/2.0 0-421170750/19/322_ 1.34001300.00.040.73 104.23.190.124h2default.:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-421170750/26/320_ 1.174801540.00.100.79 172.71.123.94h2r.commejaime.fr:443[0/0] read: stream 0, 0-421170750/20/337_ 1.211901420.00.040.77 172.70.243.74h2default.:443GET /s/13e22333e21323e2430313/_/;/META-INF/maven/com.atlassian. 0-421170750/18/319_ 1.14001350.00.040.74 35.87.126.83h2r.regimebox.fr:443[6/6] done 0-421170750/22/329_ 1.34001500.00.050.76 104.23.190.50h2default.:443GET /about HTTP/2.0 0-421170750/30/336_ 1.333202080.00.120.87 172.71.155.59h2default.:443GET / HTTP/2.0 0-421170750/23/322_ 1.184801390.00.060.76 172.71.246.155h2default.:443GET /s/13e24363e21323e2430313/_/;/META-INF/maven/com.atlassian. 0-421170750/22/337_ 1.334601420.00.070.89 172.70.130.243h2default.:443GET /blog/.git/config HTTP/2.0 0-421170750/24/331_ 1.262701360.00.130.85 172.71.95.72h2r.commejaime.be:443GET ///payment-direct-bcmc?hash=5b1389ec7f HTTP/2.0 0-421170750/24/337_ 1.284001440.00.070.86 172.71.154.187h2default.:443GET /http%3A/httpd.apache.org/docs/2.4/mod/mod_userdir.html HTT 0-421170750/28/339_ 1.274301550.00.150.91 172.71.95.71h2r.commejaime.be:443GET ///payment-direct-bcmc?hash=5b1389ec7f HTTP/2.0 0-421170750/25/330_ 1.333201360.00.070.82 172.71.155.59h2default.:443GET / HTTP/2.0 0-421170750/24/311_ 1.154101300.00.040.73 162.158.94.23h2default.:443GET /.DS_Store HTTP/2.0 0-421170750/20/330_ 1.233261440.00.060.79 172.71.172.213h2default.:443GET /telescope/requests HTTP/2.0 0-421170750/30/326_ 1.293201390.00.130.80 35.87.126.83h2r.regimebox.fr:443GET /build/1.d0cb8f43.js HTTP/2.0 0-421170750/20/325_ 1.184301690.00.040.75 172.68.194.161h2default.:443GET /info.php HTTP/2.0 0-421170750/21/330_ 1.212701360.00.030.77 172.71.246.83h2default.:443GET /.git/config HTTP/2.0 0-421170750/24/326_ 1.202701360.00.090.84 172.70.240.43h2default.:443GET /login.action HTTP/2.0 0-421170750/27/343_ 1.342401370.00.090.85 108.162.216.175h2default.:443GET /home/.git/config HTTP/2.0 0-421170750/18/319_ 1.184601350.00.030.73 172.71.172.201h2default.:443GET /.vscode/sftp.json HTTP/2.0 1-421170760/43/358_ 1.64001530.00.100.84 172.70.110.119h2default.:443GET /debug/default/view?panel=config HTTP/2.0 1-421170760/41/369_ 1.61001640.00.160.92 162.158.155.26h2default.:443GET / HTTP/2.0 1-421170760/35/352_ 1.65001590.00.080.82 162.158.159.151h2default.:443GET /debug/default/view?panel=config HTTP/2.0 1-421170760/41/344_ 1.56001420.00.160.85 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/42/357_ 1.65001540.00.080.84 162.158.62.111h2default.:443GET /v2/_catalog HTTP/2.0 1-421170760/44/377_ 1.67001570.00.130.91 104.23.187.63h2default.:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-421170760/45/360_ 1.56001750.00.160.93 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/41/375_ 1.54001660.00.160.95 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/44/367_ 1.63101570.00.180.96 162.158.158.141h2default.:443GET /server HTTP/2.0 1-421170760/38/353R 1.59101520.00.090.80 172.70.230.196h2default.:443[1/0] schedule: stream 1, GET /server-status 1-421170760/38/346_ 1.60101510.00.090.81 162.158.111.123h2default.:443GET / HTTP/2.0 1-421170760/43/348_ 1.64101520.00.160.94 172.71.246.155h2default.:443GET / HTTP/2.0 1-421170760/41/344_ 1.59101490.00.130.82 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/38/360_ 1.50001510.00.080.82 162.158.87.211h2default.:443GET /.DS_Store HTTP/2.0 1-421170760/46/360_ 1.64001500.00.100.83 172.70.251.111h2default.:443GET / HTTP/2.0 1-421170760/40/350_ 1.64101480.00.090.86 162.158.63.33h2default.:443GET /.vscode/sftp.json HTTP/2.0 1-421170760/45/358_ 1.65001550.00.090.89 172.70.111.65h2default.:443GET /v2/_catalog HTTP/2.0 1-421170760/38/358_ 1.59101510.00.080.90 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/46/370_ 1.59111570.00.130.88 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/43/360_ 1.59101700.00.100.86 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 1-421170760/45/360_ 1.64101550.00.090.84 172.70.114.205h2default.:443GET /.vscode/sftp.json HTTP/2.0 1-421170760/39/365_ 1.63101590.00.090.86 162.158.159.89h2default.:443GET /server HTTP/2.0 1-421170760/46/365_ 1.64001540.00.180.92 172.70.110.206h2default.:443GET /about HTTP/2.0 1-421170760/37/364_ 1.63001610.00.080.85 104.23.187.194h2default.:443GET /actuator/env HTTP/2.0 1-421170760/44/363_ 1.59001530.00.090.83 127.0.0.1http/1.1default.:80GET /status?full&json HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation