The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31e04679bce04679bcd4975369
Apache Status Apache Server Status for smtp.mmdoner.nl (via 46.17.7.199) Server Version: Apache/2.4.51 (Unix) OpenSSL/1.0.1e-fips Server MPM: event Server Built: Oct 8 2021 01:40:09 Current Time: Monday, 01-Aug-2022 04:27:33 CEST Restart Time: Monday, 01-Aug-2022 04:26:47 CEST Parent Server Config. Generation: 333 Parent Server MPM Generation: 332 Server uptime: 45 seconds Server load: 2.45 2.68 2.36 Total accesses: 146 - Total Traffic: 986 kB - Total Duration: 85254 CPU Usage: u526.58 s1328.14 cu446098 cs695240 - 2540000% CPU load 3.24 requests/sec - 21.9 kB/second - 6.8 kB/request - 583.932 ms/request 7 requests currently being processed, 377 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 020080no0yes064000 120081no0yes064000 220082no0yes064000 320083no0yes361000 420086no9yes460007 520088no0yes064000 Sum609 7377007 ________________________________________________________________ ________________________________________________________________ ________________________________________________________________ ___W_______________________________________________________W___W _____________________________________________W______L______W___W ________________________________________________________________ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-332200800/1/1_ 0.030220.00.000.00 68.183.75.40http/1.1localhost:80GET /.DS_Store HTTP/1.1 0-332200800/1/1_ 0.220220.00.000.00 206.81.18.165http/1.1localhost:443GET /.git/config HTTP/1.1 0-332200800/1/1_ 0.13029290.00.000.00 172.104.234.191http/1.1www.mmdoner.nl:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-332200800/2/2_ 0.180280.00.000.00 172.104.234.191http/1.1localhost:80GET /config.json HTTP/1.1 0-332200800/1/1_ 0.08020200.00.000.00 172.104.234.191http/1.1 0-332200800/1/1_ 0.170440.00.000.00 172.104.234.191http/1.1www.mmdoner.nl:80GET /login.action HTTP/1.1 0-332200800/1/1_ 0.070440.00.000.00 172.104.234.191http/1.1localhost:80GET /?rest_route=/wp/v2/users/ HTTP/1.1 0-332200800/1/1_ 0.140220.00.000.00 172.104.234.191http/1.1www.mmdoner.nl:80GET /info.php HTTP/1.1 0-332200800/2/2_ 0.190360.00.000.00 207.154.204.175http/1.1localhost:443GET /.env HTTP/1.1 0-332200800/1/1_ 0.110550.00.000.00 172.104.234.191http/1.1www.mmdoner.nl:80GET /server-status HTTP/1.1 0-332200800/2/2_ 0.210360.00.000.00 104.131.94.164http/1.1localhost:80GET /.git/config HTTP/1.1 1-332200810/1/1_ 0.220220.00.000.00 207.154.204.175http/1.1localhost:80GET /.git/config HTTP/1.1 1-332200810/1/1_ 0.240660.00.000.00 172.104.234.191http/1.1localhost:80GET / HTTP/1.1 1-332200810/1/1_ 0.0743202520250.00.010.01 136.243.228.178http/1.1www.jaffo.nl:443GET /dranken/verse-jus-dorange.html HTTP/1.1 1-332200810/1/1_ 0.280990.00.000.00 172.104.234.191http/1.1www.mmdoner.nl:80GET /s/34362e31372e372e313939/_/;/META-INF/maven/com.atlassian. 1-332200810/1/1_ 0.280220.00.000.00 172.104.234.191http/1.1www.mmdoner.nl:80GET /telescope/requests HTTP/1.1 1-332200810/1/1_ 0.29011110.00.000.00 172.104.234.191http/1.1localhost:80GET /s/34362e31372e372e313939/_/;/META-INF/maven/com.atlassian. 1-332200810/1/1_ 0.270330.00.000.00 172.104.234.191http/1.1localhost:80GET /info.php HTTP/1.1 1-332200810/1/1_ 0.230550.00.000.00 172.104.234.191http/1.1localhost:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-332200810/1/1_ 0.330550.00.010.01 206.81.18.165http/1.1localhost:443GET /server-status HTTP/1.1 1-332200810/1/1_ 0.0942000.00.040.04 185.191.171.22http/1.1www.eethuisdemolen.nl:443GET /pizza-borromea HTTP/1.1 1-332200810/1/1_ 0.320330.00.000.00 206.81.18.165http/1.1localhost:443GET /info.php HTTP/1.1 1-332200810/1/1_ 0.170220.00.000.00 68.183.75.40http/1.1localhost:80GET /telescope/requests HTTP/1.1 1-332200810/1/1_ 0.190220.00.000.00 172.104.234.191http/1.1 1-332200810/2/2_ 0.180324770.00.010.01 68.183.75.40http/1.1localhost:80GET /info.php HTTP/1.1 1-332200810/2/2_ 0.20023230.00.030.03 68.183.75.40http/1.1localhost:80GET /s/34362e31372e372e313939/_/;/META-INF/maven/com.atlassian. 1-332200810/2/2_ 0.25015190.00.000.00 172.104.234.191http/1.1www.mmdoner.nl:80GET /?rest_route=/wp/v2/users/ HTTP/1.1 2-332200820/1/1_ 0.110440.00.000.00 68.183.75.40http/1.1localhost:80GET /server-status HTTP/1.1 2-332200820/1/1_ 0.18025250.00.000.00 104.131.94.164http/1.1localhost:80GET /.env HTTP/1.1 2-332200820/2/2_ 0.210330.00.000.00 161.35.122.84http/1.1localhost:443HELP 2-332200820/1/1_ 0.15049240.00.000.00 172.104.234.191http/1.1localhost:80GET /.DS_Store HTTP/1.1 2-332200820/1/1_ 0.180330.00.000.00 104.131.94.164http/1.1localhost:80GET /s/34362e31372e372e313939/_/;/META-INF/maven/com.atlassian. 2-332200820/1/1_ 0.140440.00.000.00 207.154.204.175http/1.1localhost:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 2-332200820/1/1_ 0.220220.00.000.00 206.81.18.165http/1.1localhost:443GET / HTTP/1.1 2-332200820/3/3_ 0.2403119820.00.010.01 206.81.18.165http/1.1localhost:443GET /.env HTTP/1.1 2-332200820/2/2_ 0.240280.00.000.00 206.81.18.165http/1.1localhost:443GET /.DS_Store HTTP/1.1 2-332200820/6/6_ 0.25012160.00.050.05 206.81.18.165http/1.1localhost:443GET /s/34362e31372e372e313939/_/;/META-INF/maven/com.atlassian. 3-332200830/1/1_ 0.0540135113510.00.010.01 121.243.95.160http/1.1www.dizayn.nl:443POST /wp-login.php HTTP/1.1 3-332200831/0/0W 0.000000.00.000.00 178.128.45.181http/1.1www.mmdoner.nl:443GET / HTTP/1.1 3-332200830/1/1_ 0.930770.00.000.00 104.131.94.164http/1.1localhost:80GET /server-status HTTP/1.1 3-332200830/1/1_ 0.910660.00.000.00 104.131.94.164http/1.1localhost:80GET /.DS_Store HTTP/1.1 3-332200830/1/1_ 0.96014140.00.000.00 206.81.18.165http/1.1localhost:443GET /?rest_route=/wp/v2/users/ HTTP/1.1 3-332200830/1/1_ 0.920<
The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31e04679bce04679bce8b768b2
Apache Status Apache Server Status for smtp.mmdoner.nl (via 46.17.7.199) Server Version: Apache/2.4.51 (Unix) OpenSSL/1.0.1e-fips Server MPM: event Server Built: Oct 8 2021 01:40:09 Current Time: Monday, 01-Aug-2022 04:27:32 CEST Restart Time: Monday, 01-Aug-2022 04:26:47 CEST Parent Server Config. Generation: 333 Parent Server MPM Generation: 332 Server uptime: 44 seconds Server load: 2.41 2.68 2.35 Total accesses: 74 - Total Traffic: 889 kB - Total Duration: 81367 CPU Usage: u526.29 s1327.46 cu446098 cs695240 - 2.6e+6% CPU load 1.68 requests/sec - 20.2 kB/second - 12.0 kB/request - 1099.55 ms/request 12 requests currently being processed, 372 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 020080no0yes163000 120081no0yes064000 220082no0yes163000 320083no0yes361000 420086no0yes559000 520088no0yes262000 Sum600 12372000 _______________________________________________________________L ________________________________________________________________ _______________________________________________________________R ___________________________________________________________W_R_W ______________________R__R_____________________________L___W___L ___________R____________________________________________W_______ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-332200800/1/1_ 0.030220.00.000.00 68.183.75.40http/1.1localhost:80GET /.DS_Store HTTP/1.1 0-332200800/1/1_ 0.040330.00.000.00 207.154.204.175http/1.1localhost:80GET /telescope/requests HTTP/1.1 0-332200802/1/1L 0.050330.60.000.00 207.154.204.175http/1.1localhost:80GET /.DS_Store HTTP/1.1 1-332200810/1/1_ 0.220220.00.000.00 207.154.204.175http/1.1localhost:80GET /.git/config HTTP/1.1 1-332200810/1/1_ 0.0742202520250.00.010.01 136.243.228.178http/1.1www.jaffo.nl:443GET /dranken/verse-jus-dorange.html HTTP/1.1 1-332200810/1/1_ 0.0941000.00.040.04 185.191.171.22http/1.1www.eethuisdemolen.nl:443GET /pizza-borromea HTTP/1.1 1-332200810/1/1_ 0.170220.00.000.00 68.183.75.40http/1.1localhost:80GET /telescope/requests HTTP/1.1 1-332200810/1/1_ 0.190220.00.000.00 68.183.75.40http/1.1localhost:80GET /.git/config HTTP/1.1 1-332200810/2/2_ 0.180324770.00.010.01 68.183.75.40http/1.1localhost:80GET /info.php HTTP/1.1 1-332200810/2/2_ 0.20023230.00.030.03 68.183.75.40http/1.1localhost:80GET /s/34362e31372e372e313939/_/;/META-INF/maven/com.atlassian. 1-332200810/1/1_ 0.210440.00.000.00 68.183.75.40http/1.1localhost:80GET /login.action HTTP/1.1 2-332200820/1/1_ 0.110440.00.000.00 68.183.75.40http/1.1localhost:80GET /server-status HTTP/1.1 2-332200820/1/1_ 0.140440.00.000.00 207.154.204.175http/1.1localhost:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 2-332200820/2/2_ 0.130519500.00.010.01 207.154.204.175http/1.1localhost:80GET /?rest_route=/wp/v2/users/ HTTP/1.1 2-332200820/1/1_ 0.100550.00.000.00 68.183.75.40http/1.1localhost:80GET /?rest_route=/wp/v2/users/ HTTP/1.1 2-332200821/2/2W 0.100000.00.040.04 172.104.234.191http/1.1www.mmdoner.nl:80GET / HTTP/1.1 3-332200830/1/1_ 0.0540135113510.00.010.01 121.243.95.160http/1.1www.dizayn.nl:443POST /wp-login.php HTTP/1.1 3-332200830/1/1_ 0.4718000.00.040.04 185.191.171.40http/1.1www.dinnerandyou.be:443GET /Wraps-menu/Falafel-wrap-menu HTTP/1.1 3-332200830/1/1_ 0.3224173517350.00.010.01 54.36.148.157http/1.1www.exodusgrill.nl:443GET /extras/mayonaise.html?sort=p.price&order=ASC&limit=100 HTT 3-332200830/2/2_ 0.780327270.00.000.00 68.183.75.40http/1.1localhost:80\x16\x03\x01\x01\x01\x01 3-332200831/4/4W 0.610070330.00.100.10 157.90.177.217http/1.1www.denijl-arkel.nl:443GET /ravioli-gorgonzola.html?tag=ravioli&sort=p.price&order=ASC 3-332200830/3/3_ 0.840266390.00.050.05 207.154.204.175http/1.1localhost:80GET /info.php HTTP/1.1 3-332200831/4/4W 0.660071570.00.040.04 172.104.234.191http/1.1localhost:443GET / HTTP/1.1 3-332200830/5/5_ 0.8305111320.00.030.03 207.154.204.175http/1.1localhost:443HELP 3-332200831/4/4W 0.710092870.00.040.04 68.183.75.40http/1.1www.mmdoner.nl:443GET / HTTP/1.1 4-332200860/1/1_ 0.0538218321830.00.010.01 136.243.228.178http/1.1www.jaffo.nl:443GET /stokbrood-kebab.html HTTP/1.1 4-332200860/1/1_ 0.440000.00.000.00 172.104.234.191http/1.1localhost:80\x16\x03\x01\x01\x01\x01 4-332200860/2/2_ 0.47022220.00.000.00 207.154.204.175http/1.1localhost:80HELP 4-332200860/0/0R 0.0044000.00.000.00 172.104.234.191http/1.1 4-332200860/1/1R 0.520330.00.000.00 207.154.204.175http/1.1 4-332200860/1/1_ 0.46014140.00.000.00 68.183.75.40http/1.1localhost:80GET /.env HTTP/1.1 4-332200860/1/1_ 0.450660.00.000.00 68.183.75.40http/1.1localhost:80GET / HTTP/1.1 4-332200862/1/1L 0.530000.50.000.00 207.154.204.175http/1.1localhost:80GET / HTTP/1.1 4-332200860/2/2_ 0.420220.00.040.04 68.183.75.40http/1.1localhost:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 4-332200861/1/1W 0.121036520.00.010.01 136.243.228.178http/1.1www.jaffo.nl:443GET /stokbrood-shoarma.html HTTP/1.1 4-332200860/1/1_ 0.3211122212220.00.010.01 136.243.228.178http/1.1www.jaffo.nl:443GET /index.php?route=account/return/insert HTTP/1.1 4-332200860/3/3_ 0.300222475960.00.060.06 154.54.249.207http/1.1www.andelcentrum.nl:443GET /product/search&tag=25 HTTP/1.1 4-332200860/2/2_ 0.490343270.00.000.00 206.81.18.165http/1.1localhost:443HELP 4-332200862/6/6L 0.510480.60.110.11 68.183.75.40http/1.1localhost:80GET /config.json HTTP/1.1 5-332200880/1/1_ 0.0537156415640.00.010.01 185.191.171.34http/1.1www.denijl-arkel.nl:443GET /index.php?order=ASC&route=product%2Fsearch&sort=p.sort_ord 5-332200880/0/0R 0.0044000.00.000.00 5-332200881/0/0W 0.000000.00.000.00 207.154.204.175http/1.1localhost:80GET /server-status HTTP/1.1 5-3322008