The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31e186e174e186e174828c9b2e
Apache Status Apache Server Status for sto1.srv-cloud.net (via 89.117.18.163) Server Version: Apache/2.4.52 (Ubuntu) mod_fcgid/2.3.9 OpenSSL/3.0.2 Server MPM: event Server Built: 2024-07-17T18:57:26 Current Time: Thursday, 05-Dec-2024 08:41:41 -03 Restart Time: Thursday, 05-Dec-2024 07:25:57 -03 Parent Server Config. Generation: 2 Parent Server MPM Generation: 1 Server uptime: 1 hour 15 minutes 43 seconds Server load: 0.00 0.00 0.00 Total accesses: 20 - Total Traffic: 86 kB - Total Duration: 228 CPU Usage: u.18 s.16 cu0 cs.02 - .00792% CPU load .0044 requests/sec - 19 B/second - 4403 B/request - 11.4 ms/request 1 requests currently being processed, 49 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 01525no0yes025000 11526no0yes124000 Sum200 149000 _____________________________________________W____.............. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-115250/1/1_ 0.0051916160.00.010.01 167.94.146.53http/1.1sto1.srv-cloud.net:443GET / HTTP/1.1 0-115250/1/1_ 0.0151518180.00.010.01 167.94.146.53http/1.1sto1.srv-cloud.net:443GET / HTTP/1.1 0-115250/1/1_ 0.02514000.00.010.01 167.94.146.53http/1.1sto1.srv-cloud.net:443GET /core/img/favicon.ico HTTP/1.1 0-115250/1/1_ 0.02513000.00.000.00 167.94.146.53http/1.1sto1.srv-cloud.net:443GET /favicon.ico HTTP/1.1 0-115250/1/1_ 0.03114000.00.000.00 175.30.48.200http/1.1sto1.srv-cloud.net:80GET / HTTP/1.1 0-115250/1/1_ 0.03322220.00.010.01 142.93.129.190http/1.1sto1.srv-cloud.net:443GET / HTTP/1.1 0-115250/1/1_ 0.042000.00.000.00 142.93.129.190http/1.1sto1.srv-cloud.net:443GET /server HTTP/1.1 0-115250/1/1_ 0.041000.00.000.00 142.93.129.190http/1.1sto1.srv-cloud.net:443GET /about HTTP/1.1 0-115250/1/1_ 0.050000.00.000.00 142.93.129.190http/1.1sto1.srv-cloud.net:443GET /debug/default/view?panel=config HTTP/1.1 0-115250/1/1_ 0.050000.00.000.00 142.93.129.190http/1.1sto1.srv-cloud.net:443GET /v2/_catalog HTTP/1.1 0-115250/1/1_ 0.050000.00.000.00 142.93.129.190http/1.1sto1.srv-cloud.net:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-115260/1/1_ 0.0210061491490.00.010.01 185.242.226.109http/1.1sto1.srv-cloud.net:443GET / HTTP/1.1 1-115260/0/1_ 0.001000000.00.000.00 95.214.53.205http/1.1sto1.srv-cloud.net:80GET / HTTP/1.1 1-115260/1/1_ 0.02881000.00.000.00 194.50.16.198http/1.1sto1.srv-cloud.net:80GET /cgi-bin/index.html HTTP/1.1 1-115260/1/1_ 0.02667000.00.000.00 5.8.11.202http/1.1sto1.srv-cloud.net:80\x16\x03\x02\x01o\x01 1-115260/1/1_ 0.02514000.00.010.01 167.94.146.53http/1.1sto1.srv-cloud.net:443GET /core/img/favicon-touch.png HTTP/1.1 1-115260/0/1_ 0.00511000.00.000.00 167.94.146.53h2sto1.srv-cloud.net:443[0/0] init 1-115260/1/1_ 0.04128000.00.000.00 150.255.55.88http/1.1sto1.srv-cloud.net:80GET / HTTP/1.1 1-115260/1/1_ 0.04217170.00.010.01 142.93.129.190http/1.1sto1.srv-cloud.net:443GET / HTTP/1.1 1-115260/1/1_ 0.051000.00.000.00 142.93.129.190http/1.1sto1.srv-cloud.net:443GET /.vscode/sftp.json HTTP/1.1 1-115261/0/0W 0.000000.00.000.00 142.93.129.190http/1.1sto1.srv-cloud.net:443GET /server-status HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot mod_fcgid status: Total FastCGI processes: 0 SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 12subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 297 seconds, (range: 296...299)index usage: 0%, cache usage: 0%total entries stored since starting: 26total entries replaced since starting: 0total entries expired since starting: 13total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 1 misstotal removes since starting: 1 hit, 0 miss