The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31866d4e88866d4e88432e4c1b
Apache Status Apache Server Status for takda.philsys.gov.ph (via 10.10.20.151) Server Version: Apache/2.4.41 (Ubuntu) OpenSSL/1.1.1f Server MPM: prefork Server Built: 2023-03-08T17:32:54 Current Time: Monday, 03-Jul-2023 17:03:29 PST Restart Time: Friday, 09-Jun-2023 09:55:01 PST Parent Server Config. Generation: 25 Parent Server MPM Generation: 24 Server uptime: 24 days 7 hours 8 minutes 27 seconds Server load: 0.23 0.47 0.44 Total accesses: 4994521 - Total Traffic: 1476.2 GB - Total Duration: 1835446254 CPU Usage: u700.5 s175.28 cu263315 cs30521.6 - 14% CPU load 2.38 requests/sec - 0.7 MB/second - 309.9 kB/request - 367.492 ms/request 3 requests currently being processed, 8 idle workers W____.__._W_W................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-2410446590/494/441324W 25.895201582079270.05.93146138.03 10.10.20.150http/1.1cloud.philsys.gov.ph:8080GET /index.php/s/FfJxzPoD22o369t/download?path=/&files=CBMS%20P 1-2410446960/318/437827_ 18.6611681359628930.01.6199848.02 10.10.20.150http/1.1cloud.philsys.gov.ph:8080PROPFIND /remote.php/dav/files/mjcruz/ HTTP/1.0 2-2410261300/4769/421260_ 339.201321848538030.011160.84107876.24 10.10.20.150http/1.1cloud.philsys.gov.ph:8080GET /v2/_catalog HTTP/1.0 3-2410447540/7/431269_ 0.202331303785040.00.01101128.42 10.10.20.150http/1.1cloud.philsys.gov.ph:8080PROPFIND /remote.php/dav/files/mjcruz/Sample_Folder HTTP/1.0 4-2410445250/844/431398_ 42.700321606081100.033.75111199.14 10.10.20.150http/1.1cloud.philsys.gov.ph:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 5-24-0/0/417134. 0.0058301307181140.00.0081337.31 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 6-2410443490/1851/413345_ 96.702321297859440.0113.74114187.01 10.10.20.150http/1.1cloud.philsys.gov.ph:8080PROPFIND /remote.php/dav/files/mjcruz/ISMD%20APPLICATION HTTP/1 7-2410443880/1680/386751_ 92.652361285496680.0116.49113468.55 10.10.20.150http/1.1cloud.philsys.gov.ph:8080GET /debug/default/view?panel=config HTTP/1.0 8-24-0/0/378726. 0.0011301970843830.00.00282219.53 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 9-2410446200/703/360282_ 36.942291514758280.030.63107420.32 10.10.20.150http/1.1cloud.philsys.gov.ph:8080GET /ocs/v2.php/apps/notifications/api/v2/notifications?format= 10-2410446450/564/345596W 32.1800989334150.016.3064200.34 10.10.20.150http/1.1cloud.philsys.gov.ph:8080PROPFIND /remote.php/dav/files/dpresado/IDPMD/Back%20up%20old/V 11-2410446600/502/174261_ 26.85230686297490.06.8060090.71 10.10.20.150http/1.1cloud.philsys.gov.ph:8080GET /ocs/v2.php/core/navigation/apps?absolute=true&format=json 12-2410445130/856/133621W 47.3900588276910.056.2063240.18 10.10.20.150http/1.1cloud.philsys.gov.ph:8080GET /server-status HTTP/1.0 13-24-0/0/60150. 0.0024920215535270.00.008949.87 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 14-24-0/0/49199. 0.00111120195871850.00.0016999.19 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 15-24-0/0/26143. 0.0011924094501240.00.003377.70 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 16-24-0/0/18429. 0.00136190153580290.00.0010222.28 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 17-24-0/0/16121. 0.0013630081713400.00.004506.08 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 18-18-0/0/8231. 0.00523778044232030.00.00735.97 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 19-17-0/0/5673. 0.00607832018669210.00.00608.79 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 20-14-0/0/12862. 0.008722330146830180.00.001436.59 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 21-14-0/0/4166. 0.00872598013619060.00.00697.14 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 22-14-0/0/357. 0.0087259502311120.00.00129.39 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 23-14-0/0/2650. 0.0087251305179990.00.00442.10 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 24-14-0/0/4200. 0.00872602016370700.00.009687.86 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 25-14-0/0/2000. 0.0087260005651020.00.00465.19 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 26-14-0/0/2858. 0.0087260304693370.00.00364.97 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 27-14-0/0/28. 0.00885241074260.00.000.91 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 28-14-0/0/88. 0.008852240343140.00.003.19 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 29-14-0/0/17. 0.00885225038390.00.000.15 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 30-14-0/0/1765. 0.0088523303013990.00.00128.14 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 31-14-0/0/501. 0.008848240872370.00.0072.06 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 32-14-0/0/175. 0.008852400576540.00.0031.19 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 33-14-0/0/3069. 0.0088523005783790.00.00173.32 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 34-14-0/0/2141. 0.0088448003291270.00.00214.27 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 35-14-0/0/25. 0.008852360124470.00.000.49 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 36-14-0/0/44. 0.008852220116190.00.003.07 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 37-14-0/0/15. 0.00885245053520.00.000.68 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 38-14-0/0/347. 0.008852280467820.00.003.33 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 39-14-0/0/357. 0.008849430453110.00.0015.26 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 40-14-0/0/112. 0.008852420323340.00.0040.81 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 41-0-0/0/4. 0.002082218011100.00.000.01 ::1http/1.1cloud.philsys.gov.ph:8080OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss Apache/2.4.41 (Ubuntu) Server at takda.philsys.gov.ph Port 80
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522762f2d29
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git://git.moodle.org/moodle.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "MOODLE_401_STABLE"] remote = origin merge = refs/heads/MOODLE_401_STABLE [user] name = Your Name email = you@example.com
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522762f2d29
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git://git.moodle.org/moodle.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "MOODLE_401_STABLE"] remote = origin merge = refs/heads/MOODLE_401_STABLE [user] name = Your Name email = you@example.com