The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31d950ca5bd950ca5b53cb91f6
Apache Status Apache Server Status for shop.it (via 10.183.21.143) Server Version: Apache/2.4.52 () OpenSSL/1.0.2k-fips Server MPM: event Server Built: Dec 30 2021 21:40:08 Current Time: Wednesday, 10-Aug-2022 07:56:21 CEST Restart Time: Monday, 25-Jul-2022 17:25:03 CEST Parent Server Config. Generation: 17 Parent Server MPM Generation: 16 Server uptime: 15 days 14 hours 31 minutes 17 seconds Server load: 0.00 0.00 0.00 Total accesses: 683079 - Total Traffic: 2.7 GB - Total Duration: 12806755 CPU Usage: u29.73 s35.97 cu663.2 cs628.81 - .101% CPU load .507 requests/sec - 2135 B/second - 4214 B/request - 18.7486 ms/request 2 requests currently being processed, 73 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 0646no2yes223011 1647no0yes025000 2648no1yes025001 Sum303 273012 _______WW_______________________________________________________ ___________..................................................... ................................................................ ................................................................ ................................................................ ................................................................ ................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-166460/127/9116_ 5.342401471860.00.2133.21 127.0.0.1http/1.1127.0.0.1:80HEAD / HTTP/1.1 0-166460/133/9024_ 5.29234921486820.00.4744.56 127.0.0.1http/1.1 0-166460/143/9150_ 5.352301610510.00.1731.16 10.183.11.83http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 0-166460/140/9138_ 5.36101574330.00.2134.86 10.183.11.83http/1.1127.0.0.1:80GET / HTTP/1.1 0-166460/131/9105_ 5.39402091050.00.2034.54 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 0-166460/124/9154_ 5.30101632410.00.3035.36 10.183.12.110http/1.1127.0.0.1:80GET / HTTP/1.1 0-166460/139/9121_ 5.39001561450.00.3232.16 10.183.11.83http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 0-166462/132/9065W 5.37001532900.00.2233.97 10.183.11.83http/1.1www.shop.it:80GET /info.php HTTP/1.1 0-166462/148/9091W 5.32001624710.00.3630.50 10.183.12.110http/1.1www.shop.it:80GET /server-status HTTP/1.1 0-166460/132/9143_ 5.255401611830.00.9837.98 10.183.12.110http/1.1127.0.0.1:80GET / HTTP/1.1 0-166460/129/9120_ 5.354102183830.00.2340.05 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 0-166460/155/9180_ 5.374601948360.00.7630.70 10.183.11.83http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 0-166460/143/9036_ 5.373301584070.00.1932.72 10.183.11.83http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 0-166460/143/9170_ 5.314101530080.00.4535.85 10.183.11.83http/1.1127.0.0.1:80GET / HTTP/1.1 0-166460/142/9079_ 5.355402155820.00.1945.27 10.183.11.83http/1.1127.0.0.1:80GET / HTTP/1.1 0-166460/142/9082_ 5.315401552680.00.5649.62 10.183.11.83http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 0-166460/145/9226_ 5.352801661850.00.5248.94 10.183.11.83http/1.1127.0.0.1:80GET / HTTP/1.1 0-166460/130/9137_ 5.3731331588670.00.3333.49 10.183.12.110http/1.1glasscleaner.triboo.direct:80GET /robot_lavavetri/?utm_source=dem&utm_postback=102b223267ca3 0-166460/123/9098_ 5.312802282100.00.1528.40 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 0-166460/133/9078_ 5.372801437020.00.2631.07 10.183.12.110http/1.1www.studielauree.it:80GET /uni-today/img/studi-e-lauree-logo.png HTTP/1.1 0-166460/148/9175_ 5.372802759360.00.5140.74 10.183.11.83http/1.1127.0.0.1:80GET / HTTP/1.1 0-166460/142/9117_ 5.3728461483400.00.2940.54 10.183.12.110http/1.1www.bridgetodel.com:80POST /api/koi_job/index.php?op=subscribe HTTP/1.1 0-166460/138/9027_ 5.362831586930.00.3146.11 10.183.11.83http/1.1www.saving.direct:80GET /.well-known/apple-app-site-association HTTP/1.1 0-166460/136/8979_ 5.372401534310.00.1045.89 10.183.12.110http/1.1127.0.0.1:80GET / HTTP/1.1 0-166460/132/9234_ 5.38602161280.00.1748.47 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/14/4555_ 3.31430371265540.00.0422.86 10.183.11.83http/1.1elletistore.triboo.direct:80GET /sensor-cleaner/?utm_source=dem&utm_postback=10252920c6f887 1-166470/13/4538_ 3.502560695780.00.2817.86 10.183.11.83http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/19/4547_ 3.502530673140.00.0416.52 10.183.11.83http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/19/4580_ 3.332480651120.00.0723.42 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/14/4510_ 3.342481757490.00.0214.97 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/23/4647_ 3.502340678370.00.0221.80 10.183.12.110http/1.1127.0.0.1:80GET / HTTP/1.1 1-166470/12/4516_ 3.5023401265280.00.0219.75 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/16/4519_ 3.122340719030.00.0042.76 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/17/4557_ 3.362291745690.00.0228.04 10.183.12.110http/1.1finanziamenti.sicheconviene.it:GET /sogni-birthplace/img/striscia.svg HTTP/1.1 1-166470/17/4550_ 3.362290700440.00.0515.31 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/14/4490_ 3.5121121349150.00.0016.74 10.183.11.83http/1.1www.studielauree.it:80GET /uni-today/img/studi-e-lauree-logo.png HTTP/1.1 1-166470/16/4584_ 3.122060868340.00.0218.36 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/17/4559_ 3.3820601568800.00.0416.74 10.183.11.83http/1.1127.0.0.1:80GET / HTTP/1.1 1-166470/16/4601_ 3.531390739560.00.0014.50 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/22/4592_ 3.541370739070.00.0220.77 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/13/4687_ 2.951320725680.00.0316.50 10.183.12.110http/1.1127.0.0.1:80GET / HTTP/1.1 1-166470/17/4632_ 3.151320626360.00.0015.33 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/14/4535_ 3.256901261860.00.2717.62 10.183.11.83http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/23/4634_ 3.55740836980.00.0316.84 10.183.12.110http/1.1www.saving.direct:80GET /robots.txt HTTP/1.1 1-166470/15/4539_ 3.41692738790.00.0217.97 10.183.11.83http/1.1www.prestitone.it:80GET / HTTP/1.1 1-166470/17/4664_ 3.561621897910.00.0418.01 10.183.12.110http/1.1diploma.studielauree.it:80GET /2021//03/?utm_source=google_ads_search&gclid=CjwKCAjwi8iXB 1-166470/20/4651_ 3.56140962040.00.0216.96 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/15/4574_ 3.5690843450.00.0216.15 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-166470/16/4474_ 3.4640717930.00.0615.59 10.183.12.110http/1.1www.radionerazzurra.it:80GET / HTTP/1.1 1-16</
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d623e844a623e844a623e844a623e844a
Found 1 files trough .DS_Store spidering: /chat