The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31579960d9579960d92ddaefee
Apache Status Apache Server Status for reporting.itzontarget.com (via 127.0.0.1) Server Version: Apache/2.4.54 () OpenSSL/1.0.2k-fips Server MPM: prefork Server Built: Jun 30 2022 11:02:23 Current Time: Wednesday, 18-Jan-2023 09:14:45 UTC Restart Time: Wednesday, 18-Jan-2023 04:11:08 UTC Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 5 hours 3 minutes 37 seconds Server load: 0.24 0.25 0.33 Total accesses: 58316 - Total Traffic: 478.0 MB - Total Duration: 31966408 CPU Usage: u1273.12 s512.65 cu575.99 cs4792.73 - 39.3% CPU load 3.2 requests/sec - 26.9 kB/second - 8.4 kB/request - 548.158 ms/request 8 requests currently being processed, 25 idle workers __W.W__.__WKWKK________K____.._.______.......................... ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-01470/2175/2175_ 234.8503139881420.021.7721.77 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 1-01660/1781/1781_ 237.58807689840.08.388.38 localhosthttp/1.1localhost:80GET /server-status/?auto HTTP/1.1 2-017568/2312/2312W 226.462130959013145.015.8915.89 127.0.0.1http/1.1localhost:80GET /app/dash/setup/masterservicemapper_account_list?service_id 3-0-0/0/617. 0.00732603356710.00.0019.95 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 4-01870/1753/1753W 230.2818308017030.09.319.31 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 5-01930/1785/1785_ 211.12453239004140.07.817.81 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 6-01990/2092/2092_ 270.313932211311190.030.1830.18 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 7-0-0/0/532. 0.007413038422010.00.005.09 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 8-02110/2028/2028_ 218.78273137841600.017.4917.49 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 9-02170/1774/1774_ 218.59363127714040.010.8610.86 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 10-02230/596/596W 118.42923403887690.05.055.05 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 11-022516/1716/1716K 282.553144145873232.37.667.66 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/test_uptime HTTP/1.1 12-023511/1970/1970W 235.070086299424.810.0810.08 127.0.0.1http/1.1localhost:80GET /server-status HTTP/1.1 13-024154/1661/1661K 227.8700720024117.09.909.90 127.0.0.1http/1.1localhost:80GET /.env HTTP/1.1 14-024331/1571/1571K 217.890088518064.010.7710.77 127.0.0.1http/1.1localhost:80GET /telescope/requests HTTP/1.1 15-02530/2092/2092_ 244.85479410421490.019.3619.36 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_specific_data_by_service?k 16-02930/2065/2065_ 216.69303138799110.09.849.84 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 17-04480/1975/1975_ 348.31308820412230.010.2910.29 127.0.0.1http/1.1localhost:80GET /app/fetcher/cron/fetchbyservicepartial/id/251 HTTP/1.1 18-04580/1752/1752_ 236.51483148040260.023.5723.57 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 19-04640/2058/2058_ 222.81631110494770.08.738.73 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 20-06030/1788/1788_ 231.25213147774600.012.9812.98 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 21-06590/2321/2321_ 233.152431212178940.019.5619.56 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 22-06650/1697/1697_ 218.2527876962160.09.849.84 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/test_uptime HTTP/1.1 23-057266/2171/2171K 229.472136103202412.420.7520.75 127.0.0.1http/1.1localhost:80GET /server/api/dash/widgets/sparklineoptions?sql=1 HTTP/1.1 24-0232950/1920/1920_ 200.03423107623090.015.3715.37 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 25-0437130/1457/1457_ 195.3910906832190.07.547.54 127.0.0.1http/1.1localhost:80GET /app/fetcher/cron/is_daily_fetch_complete?date=2023-01-18&s 26-0437250/1733/1733_ 192.0733898077340.016.5116.51 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_specific_data_by_service?k 27-0437310/1641/1641_ 192.69183448440910.08.158.15 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 28-0-0/0/311. 0.00732501983450.00.005.29 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 29-0-0/0/156. 0.0073790794680.00.001.76 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 30-01212250/1499/1499_ 123.89333146533630.014.6914.69 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 31-0-0/0/477. 0.00499301689430.00.000.93 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 32-01599910/1275/1275_ 97.77153244664580.010.5710.57 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 33-01599970/1501/1501_ 91.62123105387060.07.097.09 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 34-01600380/1168/1168_ 97.914744094780460.04.344.34 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_status?key=4c8fc4eacae79b8 35-01600440/1063/1063_ 92.4433283509020.02.842.84 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 36-01600500/795/795_ 92.14261003946960.027.0627.06 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_specific_data_by_service?k 37-01600560/1038/1038_ 84.4893124012190.030.7630.76 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31579960d9579960d972416885
Apache Status Apache Server Status for reporting.itzontarget.com (via 127.0.0.1) Server Version: Apache/2.4.54 () OpenSSL/1.0.2k-fips Server MPM: prefork Server Built: Jun 30 2022 11:02:23 Current Time: Monday, 19-Sep-2022 14:13:31 UTC Restart Time: Saturday, 17-Sep-2022 02:05:57 UTC Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 2 days 12 hours 7 minutes 33 seconds Server load: 6.04 5.15 3.16 Total accesses: 557307 - Total Traffic: 4.6 GB - Total Duration: 464648320 CPU Usage: u4870.89 s1505.24 cu25135.4 cs64604.4 - 44.4% CPU load 2.57 requests/sec - 22.5 kB/second - 8.7 kB/request - 833.739 ms/request 14 requests currently being processed, 27 idle workers _KKW____W_._WW______W.W__W_K_____W_WK..___....._.W.............. ......................_......................................... ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-034455760/61/15987_ 8.642577107701830.00.22210.24 127.0.0.1http/1.1localhost:80GET /app/iotool/flights/getFlights?lineItemId=1954 HTTP/1.1 1-033858971/536/12940K 85.6021134267884.63.52124.52 127.0.0.1http/1.1localhost:80GET /client/iotool/app/scripts/plugins/graph-editor/js/io/mxDef 2-0341539624/343/17007K 55.980708816101117.82.34114.27 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_specific_data_by_service?k 3-030424932/4181/10999W 491.00168065014354.118.2077.41 127.0.0.1http/1.1localhost:80GET /server/api/categories/55/data/56/values/distinct?fields=ca 4-030425130/3852/14265_ 493.434036981498530.030.53139.52 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 5-034168520/250/17324_ 50.871637097403180.06.45225.14 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 6-033833530/654/11409_ 104.611036962040970.019.2683.29 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 7-032731450/2094/12960_ 263.9617210675771450.032.54125.41 127.0.0.1http/1.1localhost:80GET /server/api/services/1000017/data/cgn?daterange=2022-08-20% 8-033312172/1201/9477W 171.301053483085.67.3866.40 127.0.0.1http/1.1localhost:80GET /server/api/dash/pages?all=true&extra=false&is_dynamic=true 9-033474410/1129/11304_ 183.2825109859186100.06.45129.45 127.0.0.1http/1.1localhost:80GET /server/api/services/1000043/data/cgn?aggregate=false&datat 10-0-0/0/7124. 0.0076036701150.00.0050.95 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 11-033833700/782/16870_ 257.01736488828900.012.07140.41 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 12-0343534350/275/6003W 42.03002863067239.53.2641.82 127.0.0.1http/1.1localhost:80GET /server-status HTTP/1.1 13-0339784329/464/17213W 201.6814801136911785.02.61131.57 127.0.0.1http/1.1localhost:80GET /app/dash/setup/masterservicemapper_account_list?service_id 14-019918500/7026/14014_ 1176.8319084188100.040.54119.60 localhosthttp/1.1localhost:80GET /server-status/?auto HTTP/1.1 15-033663780/750/10184_ 123.8737380158726910.06.0466.50 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 16-034503020/26/12627_ 5.29788130018200.00.07104.48 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_specific_data_by_service?k 17-034455960/55/6178_ 13.143438829169390.00.5765.45 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 18-034062400/525/11855_ 77.89799132998580.05.6069.84 127.0.0.1http/1.1localhost:80GET /server/api/clusters/values/distinct?fields=name&status=act 19-034062460/374/17864_ 165.3313389123327940.01.96112.06 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 20-0202550/17353/17353W 3201.963011225442255.7248.09248.09 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_status?key=8338f28563a882c 21-0-0/0/5216. 0.0086025531350.00.0030.06 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 22-0340790217/378/11359W 56.411630545615153.07.5373.51 127.0.0.1http/1.1localhost:80GET /server/api/categories/55/data/56/values/distinct?fields=ca 23-034079080/451/14074_ 59.4819384827505210.03.7398.29 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 24-034353650/177/10105_ 21.071719486848800.00.9053.42 127.0.0.1http/1.1localhost:80GET /server/api/services/72/data/cgn?aggregate=true&daterange=2 25-034353712/182/16035W 22.371092386475.80.8589.75 127.0.0.1http/1.1localhost:80GET /server/api/categories/62/data/64?aggregate=false&datatable 26-034354280/140/3857_ 20.80439522212930.00.6124.97 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 27-0345030825/35/6739K 2.0020355813078.70.1140.24 127.0.0.1http/1.1localhost:80GET /client/iotool/app/scripts/plugins/graph-editor/js/shape/mx 28-034456670/43/5010_ 5.341712320528190.00.3034.31 127.0.0.1http/1.1localhost:80GET /server/api/enums/relativedateranges HTTP/1.1 29-034503870/19/14722_ 2.849100135404540.00.05166.55 127.0.0.1http/1.1localhost:80GET /server/api/dash/dashboardfilters/view HTTP/1.1 30-034503930/2/12208_ 0.9225405146093530.00.0075.16 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 31-034355460/123/12104_ 18.4832061621370.00.6779.32 127.0.0.1http/1.1localhost:80GET /client/core/app/images/report.png HTTP/1.1 32-033737440/747/9415_ 114.323138652512340.04.4353.76 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 33-034503999/10/4911W 1.30240205892824.20.0228.85 127.0.0.1http/1.1localhost:80GET /server/api/categories/58/data/37?aggregate=false&datatable 34-019920340/7178/7180_ 1233.86138943014450.072.2572.25 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 35-0337385922/752/757W 296.1535101397396109.912.0712.07 127.0.0.1http/1.1localhost:80GET /server/api/services/61/data/geo?datatable=0&timegrouping=d 36-0345040533/34/5921K 4.421933422008312.10.3135.58 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_specific_data_by_service?k 37-0-0/0/5031. 0.0082036164530.00.0045.00 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 38-0-0/0/6527. 0.002707041849980.00.0037.29 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 39-033739650/799/3117_ 122.7698519967110.03.5228.27 127.0.0.1http/1.1localhost:80GET /app/dash/instanceManagement/get_recent_fetch_log?key=3796b 40-011742130/12600/12601_ 1981.6616103125079960.0105.15105.15 127.0.0.1http/1.1localhost:80GET /app/iotool/clients/client?id=2952 HTTP/1.1 41-033739710/910/1761_ 115.5617174815100370.04.977.27 127.0.0.1http/1.1localhost:80GET /server/api/services/1000017/data/cgn?aggregate=false&datat 42-0-0/0/12715. 0.002023080899850.00.0099.86 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 43-0-0/0/5286. 0.0083826047319080.00.0029.47 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 44-0-0/0/6. 0.008489806910.00.000.01 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 45-0-0/0/5637. 0.0084878022873170.00.0043.31 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 46-0-0/0/11173. 0.002695073381290.00.00129.87 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 47-08605610/12575/12575_ 2100.442237888201690.096.2696.26 127.0.0.1http/1.1localhost:80GET /get_version.php HTTP/1.1 48-0-0/0/6. 0.0084922017630.00.000.01 127.0.0.1http/1.1localhost:80OPTIONS * HTTP/1.0 49-0199241037/7443/7444