No description available
Severity: medium
Fingerprint: c72c1c3018e67f2f18e67f2f9d6971f19d6971f1b4c5182fb4c5182f26e6e89c
Apache Status Apache Server Status for test.main-vip.de.wolf.eu (via 172.21.0.4) Server Version: Apache/2.4.51 (Debian) PHP/7.4.26 OpenSSL/1.1.1k Server MPM: prefork Server Built: 2021-10-07T17:49:44 Current Time: Tuesday, 15-Feb-2022 18:33:32 UTC Restart Time: Tuesday, 08-Feb-2022 09:20:49 UTC Parent Server Config. Generation: 17 Parent Server MPM Generation: 16 Server uptime: 7 days 9 hours 12 minutes 43 seconds Server load: 0.20 0.21 0.10 Total accesses: 10439 - Total Traffic: 693.8 MB - Total Duration: 6052200 CPU Usage: u50.4 s42.87 cu47462.6 cs8921.55 - 8.85% CPU load .0164 requests/sec - 1140 B/second - 68.1 kB/request - 579.768 ms/request 6 requests currently being processed, 5 idle workers _WRR___R._RW.................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-1619630/22/983_ 16.1113414838070.00.37138.55 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET / HTTP/1.1 1-1619840/16/1002W 9.38006757770.00.15208.42 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 2-1619860/8/691R 2.2693014894560.00.059.74 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET / HTTP/1.1 3-1619870/7/970R 2.3855654752030.00.0566.68 192.168.1.1http/1.1 4-1619590/17/947_ 5.2307646006940.00.1626.66 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 5-1632970/0/908_ 0.00005635430.00.0017.01 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 6-1619880/28/821_ 1.53004672840.00.0511.55 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e 7-1619580/9/937R 5.16704782550.00.0766.69 192.168.1.1http/1.1 8-16-0/0/412. 0.001122802081940.00.008.13 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 9-1619610/10/567_ 2.37302809000.00.387.76 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e 10-1619620/8/503R 1.0226802292490.00.0324.33 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e 11-1619920/14/652W 8.91003960020.00.1285.11 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /server-status HTTP/1.1 12-15-0/0/297. 0.001672201785710.00.006.40 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 13-15-0/0/184. 0.00167210686370.00.005.41 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 14-15-0/0/62. 0.0016720091810.00.000.13 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 15-15-0/0/309. 0.001671902712390.00.006.69 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 16-15-0/0/156. 0.001476101617560.00.003.77 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 17-6-0/0/1. 0.00498345000.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 18-6-0/0/36. 0.00467974645144420.00.000.76 192.168.1.1http/1.1test.main.de.wolf.eu:443GET /admin/misc/ping?_dc=1644481877966 HTTP/1.1 19-6-0/0/1. 0.00498418000.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 12subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 227 seconds, (range: 16...299)index usage: 0%, cache usage: 0%total entries stored since starting: 20total entries replaced since starting: 0total entries expired since starting: 7total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 48 misstotal removes since starting: 1 hit, 1 miss Apache/2.4.51 (Debian) Server at test.main-vip.de.wolf.eu Port 443
Severity: medium
Fingerprint: c72c1c3018e67f2f18e67f2f9d6971f19d6971f1b4c5182fb4c5182fb88ed32e
Apache Status Apache Server Status for test.main-vip.de.wolf.eu (via 172.21.0.4) Server Version: Apache/2.4.51 (Debian) PHP/7.4.24 OpenSSL/1.1.1k Server MPM: prefork Server Built: 2021-10-07T17:49:44 Current Time: Saturday, 20-Nov-2021 13:28:02 UTC Restart Time: Friday, 22-Oct-2021 08:08:38 UTC Parent Server Config. Generation: 78 Parent Server MPM Generation: 77 Server uptime: 29 days 5 hours 19 minutes 24 seconds Server load: 0.56 0.14 0.04 Total accesses: 73650 - Total Traffic: 2.4 GB - Total Duration: 41306869 CPU Usage: u120.38 s110.47 cu93277.3 cs23545.7 - 4.64% CPU load .0292 requests/sec - 1008 B/second - 33.8 kB/request - 560.854 ms/request 2 requests currently being processed, 8 idle workers _W_R______...................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-77248650/91/6605_ 16.143102036477420.01.39413.92 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 1-77248680/61/6320W 13.180035534800.01.56220.97 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /server-status HTTP/1.1 2-77274670/11/6369_ 2.86487835415090.00.15150.17 192.168.1.1http/1.1 3-77248700/140/6380R 23.039036041310.02.08217.29 192.168.1.1http/1.1 4-77249710/85/6197_ 19.92082031490960.00.66195.53 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /favicon.ico HTTP/1.1 5-77248750/36/6167_ 10.413034364840.00.58284.22 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e 6-77273710/25/6429_ 7.774037061480.00.48148.97 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e 7-77248770/75/5831_ 19.730032278180.01.64149.23 192.168.1.1http/1.1 8-77248670/104/6500_ 16.84090333763060.00.86154.18 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 9-77273900/18/5093_ 5.69462329367980.00.09108.46 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET / HTTP/1.1 10-77-0/0/4045. 0.0056025021675620.00.00206.34 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 11-77-0/0/2864. 0.0059363017721410.00.0053.49 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 12-77-0/0/1764. 0.0059362010548650.00.0042.20 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 13-77-0/0/1296. 0.005936107365440.00.0019.58 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 14-77-0/0/330. 0.005714003785360.00.0011.51 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 15-70-0/0/614. 0.0025883804489160.00.0018.61 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 16-70-0/0/222. 0.0027567001357510.00.006.18 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 17-70-0/0/439. 0.001841155502772690.00.0020.16 192.168.1.1http/1.1test.main.de.wolf.eu:443GET /admin/notification/find-last-unread?_dc=1637227846924&last 18-70-0/0/57. 0.002756910421710.00.001.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 19-70-0/0/25. 0.002756930230230.00.000.32 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 20-70-0/0/16. 0.002756900171980.00.000.11 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 21-70-0/0/11. 0.002756890351510.00.000.02 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 22-70-0/0/3. 0.00275673011040.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 23-70-0/0/3. 0.00275688020.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 24-70-0/0/13. 0.00275375043430.00.001.33 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 25-70-0/0/10. 0.002756670380.00.001.48 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 26-70-0/0/40. 0.002748570327080.00.002.93 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 27-70-0/0/7. 0.002756710220.00.000.94 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 11subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 293 seconds, (range: 287...297)index usage: 0%, cache usage: 0%total entries stored since starting: 57total entries replaced since starting: 0total entries expired since starting: 46total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 128 misstotal removes since starting: 0 hit, 7 miss Apache/2.4.51 (Debian) Server at test.main-vip.de.wolf.eu Port 443
Severity: medium
Fingerprint: c72c1c3018e67f2f18e67f2f9d6971f19d6971f1b4c5182fb4c5182f448b79c0
Apache Status Apache Server Status for test.main-vip.de.wolf.eu (via 172.21.0.4) Server Version: Apache/2.4.51 (Debian) PHP/7.4.24 OpenSSL/1.1.1k Server MPM: prefork Server Built: 2021-10-07T17:49:44 Current Time: Monday, 25-Oct-2021 11:35:13 UTC Restart Time: Friday, 22-Oct-2021 08:08:38 UTC Parent Server Config. Generation: 7 Parent Server MPM Generation: 6 Server uptime: 3 days 3 hours 26 minutes 34 seconds Server load: 0.16 0.18 0.10 Total accesses: 2631 - Total Traffic: 279.4 MB - Total Duration: 1280714 CPU Usage: u22.82 s13.43 cu14661 cs2691.55 - 6.4% CPU load .00969 requests/sec - 1078 B/second - 108.7 kB/request - 486.778 ms/request 1 requests currently being processed, 9 idle workers _W____.____..................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-6272640/10/209_ 1.751973827390.00.466.90 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /telescope/requests HTTP/1.1 1-6272590/8/294W 1.12001535120.00.8567.23 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /server-status HTTP/1.1 2-6272660/8/185_ 2.30010271405820.00.607.81 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /v2/_catalog HTTP/1.1 3-6272600/10/303_ 1.22301565670.00.4984.19 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e 4-6272610/14/236_ 9.02210831435420.00.5763.79 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 5-6272670/11/224_ 2.1119511071250.00.6113.57 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /debug/default/view?panel=config HTTP/1.1 6-6-0/0/175. 0.0036490899080.00.005.94 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 7-6272700/10/259_ 1.24301148600.00.847.54 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e 8-6272620/7/285_ 1.6209291021150.00.466.52 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /api/search?folderIds=0 HTTP/1.1 9-6272630/16/259_ 5.3521015977210.01.006.88 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 10-6272750/3/180_ 0.5240841610.00.037.74 192.168.1.1http/1.1 11-4-0/0/22. 0.0024884851878750.00.001.27 192.168.1.1http/1.1test.main.de.wolf.eu:443GET /admin/misc/ping?_dc=1634911561735 HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 4subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 293 seconds, (range: 292...293)index usage: 0%, cache usage: 0%total entries stored since starting: 14total entries replaced since starting: 0total entries expired since starting: 9total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 56 misstotal removes since starting: 1 hit, 3 miss Apache/2.4.51 (Debian) Server at test.main-vip.de.wolf.eu Port 443
Severity: medium
Fingerprint: c72c1c3018e67f2f18e67f2f9d6971f19d6971f1b4c5182fb4c5182f97b8a472
Apache Status Apache Server Status for test.main-vip.de.wolf.eu (via 172.21.0.4) Server Version: Apache/2.4.48 (Debian) PHP/7.4.23 OpenSSL/1.1.1k Server MPM: prefork Server Built: 2021-08-12T11:51:47 Current Time: Wednesday, 06-Oct-2021 17:40:30 UTC Restart Time: Tuesday, 05-Oct-2021 09:46:59 UTC Parent Server Config. Generation: 9 Parent Server MPM Generation: 8 Server uptime: 1 day 7 hours 53 minutes 30 seconds Server load: 0.11 0.08 0.05 Total accesses: 9527 - Total Traffic: 817.8 MB - Total Duration: 6413143 CPU Usage: u100.63 s48.41 cu7255.82 cs1718.08 - 7.95% CPU load .083 requests/sec - 7.3 kB/second - 87.9 kB/request - 673.154 ms/request 2 requests currently being processed, 8 idle workers C.____W__._._................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-8102521/74/766C 24.3507236188557.31.5865.70 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET / HTTP/1.1 1-8-0/0/790. 0.001016405767290.00.00153.84 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 2-8103140/57/822_ 20.3528044861100.00.4515.83 192.168.1.1http/1.1 3-8102480/20/823_ 6.6127855618770.00.6516.57 192.168.1.1http/1.1 4-8102470/80/876_ 23.49005318290.02.2028.85 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e 5-8103150/83/716_ 21.6308694733970.01.4414.89 192.168.1.1http/1.1 6-8103170/23/742W 4.93004600150.00.8393.39 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /server-status HTTP/1.1 7-8103300/9/473_ 4.3029063304600.00.11126.07 192.168.1.1http/1.1 8-8103290/9/727_ 3.2927504312300.00.0615.64 192.168.1.1http/1.1 9-7-0/0/668. 0.00105825294653760.00.0067.39 192.168.1.1http/1.1test.main.de.wolf.eu:443GET /admin/asset/get-image-thumbnail?id=5721&alt=&width=600&asp 10-8102500/64/563_ 18.1909724716000.01.0112.80 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 11-7-0/0/262. 0.001561202044210.00.004.93 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 12-8102510/67/569_ 17.1515444586190.00.68187.83 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET / HTTP/1.1 13-7-0/0/240. 0.002193801306980.00.005.87 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 14-6-0/0/49. 0.00298070251360.00.000.85 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 15-7-0/0/64. 0.00271220287790.00.000.57 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 16-6-0/0/19. 0.00275541038162300.00.000.08 192.168.1.1http/1.1test.main-vip.de.wolf.eu:443GET / HTTP/1.1 17-6-0/0/58. 0.00275546840362610.00.000.63 192.168.1.1http/1.1test.main.de.wolf.eu:443GET /admin/notification/find-last-unread?_dc=1633514344967&last 18-6-0/0/50. 0.0029863057440.00.000.39 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 19-6-0/0/1. 0.0038832000.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 20-6-0/0/27. 0.0038805077900.00.000.07 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 21-6-0/0/65. 0.00387210343210.00.001.89 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 22-6-0/0/68. 0.00381740285250.00.001.75 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 23-6-0/0/63. 0.00387390237230.00.001.94 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 24-6-0/0/25. 0.0038811054040.00.000.07 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 25-6-0/0/1. 0.0038831000.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 4subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 255 seconds, (range: 131...298)index usage: 0%, cache usage: 0%total entries stored since starting: 11total entries replaced since starting: 0total entries expired since starting: 6total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 36 misstotal removes since starting: 1 hit, 2 miss Apache/2.4.48 (Debian) Server at test.main-vip.de.wolf.eu Port 443
The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb317ff2a2ef7ff2a2efae1bcdfb
Apache Status Apache Server Status for test.main-vip.de.wolf.eu (via 172.21.0.4) Server Version: Apache/2.4.54 (Debian) PHP/7.4.30 OpenSSL/1.1.1n Server MPM: prefork Server Built: 2022-06-09T04:26:43 Current Time: Saturday, 10-Dec-2022 06:11:53 UTC Restart Time: Friday, 09-Dec-2022 12:12:21 UTC Parent Server Config. Generation: 2 Parent Server MPM Generation: 1 Server uptime: 17 hours 59 minutes 31 seconds Server load: 0.19 0.15 0.11 Total accesses: 1009 - Total Traffic: 23.8 MB - Total Duration: 1021072 CPU Usage: u116.63 s48.06 cu41.47 cs16.85 - .344% CPU load .0156 requests/sec - 385 B/second - 24.1 kB/request - 1011.96 ms/request 12 requests currently being processed, 0 idle workers W.RWWRWCWWWWW................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-116240/84/84W 27.3300736180.03.363.36 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.env HTTP/1.1 1-1-0/0/110. 0.0000465720.00.003.85 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 2-116260/114/114R 22.46001718490.03.343.34 10.49.100.254http/1.1 3-116270/73/73W 21.4100525900.01.151.15 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443PUT /api/v2/cmdb/system/admin/admin HTTP/1.1 4-137980/2/56W 0.51002068510.00.011.78 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /server-status HTTP/1.1 5-116290/117/117R 20.9510476400.01.891.89 10.49.100.254http/1.1 6-121760/96/121W 14.16002552010.00.921.60 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 7-121521/53/58C 13.1300343950.20.640.69 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 8-122300/42/46W 11.1500273430.00.410.43 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.git/config HTTP/1.1 9-116340/121/121W 26.1900625210.02.092.09 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /telescope/requests HTTP/1.1 10-123800/17/47W 4.2900253030.00.182.94 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /info.php HTTP/1.1 11-137990/1/62W 0.0000171820.00.000.68 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET / HTTP/1.1 12-138000/0/0W 0.000000.00.000.00 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /?rest_route=/wp/v2/users/ HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 10subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 228 seconds, (range: 200...299)index usage: 0%, cache usage: 0%total entries stored since starting: 60total entries replaced since starting: 0total entries expired since starting: 50total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 171 misstotal removes since starting: 0 hit, 2 miss Apache/2.4.54 (Debian) Server at test.main-vip.de.wolf.eu Port 443
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb317ff2a2ef7ff2a2ef2e70f0ed
Apache Status Apache Server Status for test.main-vip.de.wolf.eu (via 172.21.0.4) Server Version: Apache/2.4.54 (Debian) PHP/7.4.30 OpenSSL/1.1.1n Server MPM: prefork Server Built: 2022-06-09T04:26:43 Current Time: Monday, 10-Oct-2022 09:59:46 UTC Restart Time: Tuesday, 26-Jul-2022 13:54:48 UTC Parent Server Config. Generation: 85 Parent Server MPM Generation: 84 Server uptime: 75 days 20 hours 4 minutes 58 seconds Server load: 0.03 0.15 0.18 Total accesses: 123091 - Total Traffic: 3.8 GB - Total Duration: 148528992 CPU Usage: u219 s396.8 cu189030 cs47948 - 3.63% CPU load .0188 requests/sec - 618 B/second - 32.2 kB/request - 1206.66 ms/request 10 requests currently being processed, 0 idle workers WWWWRRW.WWW..................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-8433470/32/10993W 9.3700103462870.00.11276.47 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.env HTTP/1.1 1-8432400/49/10810W 14.580077133340.00.16128.14 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /s/39332e3132322e37302e313032/_/;/META-INF/maven/com.atlass 2-84253660/161/10129W 30.3300116426340.02.21510.99 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 3-84254610/114/10344W 20.5600182884760.00.76444.09 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 4-8436130/6/10137R 1.240089618260.00.02542.39 10.49.100.254http/1.1 5-8432480/46/10024R 14.260094011010.00.26292.67 10.49.100.254http/1.1 6-8435900/10/9678W 2.5400159788790.00.04357.84 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /telescope/requests HTTP/1.1 7-84-0/0/8859. 0.00102320142932000.00.00293.04 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 8-84253630/172/10068W 26.240090210360.01.93186.29 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.git/config HTTP/1.1 9-84259270/173/8571W 31.9900113095640.01.78312.34 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /server-status HTTP/1.1 10-84259320/90/8813W 21.5800101588370.00.96159.38 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET / HTTP/1.1 11-84-0/0/5153. 0.001047060649280.00.00160.73 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 12-84-0/0/3812. 0.007295055414440.00.0040.43 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 13-82-0/0/2779. 0.00268948050193400.00.00130.64 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 14-82-0/0/744. 0.0025965822604062330.00.006.30 10.49.100.254http/1.1test.main.de.wolf.eu:443GET /admin/notification/find-last-unread?_dc=1665136299422&last 15-81-0/0/689. 0.00337246023918540.00.008.22 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 16-81-0/0/555. 0.0033726703582860.00.007.82 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 17-80-0/0/349. 0.0042793801210940.00.002.10 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 18-80-0/0/99. 0.004279370700680.00.001.30 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 19-80-0/0/5. 0.00427936010.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 20-80-0/0/6. 0.004279350383330.00.000.03 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 21-80-0/0/7. 0.00427841025070.00.000.11 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 22-82-0/0/353. 0.00269034013495300.00.005.42 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 23-80-0/0/3. 0.00427907060.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 24-80-0/0/11. 0.00427842093620.00.000.19 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 25-80-0/0/100. 0.004241330408180.00.000.40 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 11subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 230 seconds, (range: 208...299)index usage: 0%, cache usage: 0%total entries stored since starting: 162total entries replaced since starting: 0total entries expired since starting: 151total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 464 misstotal removes since starting: 0 hit, 45 miss Apache/2.4.54 (Debian) Server at test.main-vip.de.wolf.eu Port 443
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb317ff2a2ef7ff2a2eff9307470
Apache Status Apache Server Status for test.main-vip.de.wolf.eu (via 172.21.0.4) Server Version: Apache/2.4.54 (Debian) PHP/7.4.30 OpenSSL/1.1.1n Server MPM: prefork Server Built: 2022-06-09T04:26:43 Current Time: Wednesday, 10-Aug-2022 22:43:05 UTC Restart Time: Tuesday, 26-Jul-2022 13:54:48 UTC Parent Server Config. Generation: 18 Parent Server MPM Generation: 17 Server uptime: 15 days 8 hours 48 minutes 17 seconds Server load: 0.07 0.08 0.08 Total accesses: 20998 - Total Traffic: 404.5 MB - Total Duration: 13369503 CPU Usage: u149.16 s123.39 cu43244.2 cs9942.78 - 4.03% CPU load .0158 requests/sec - 319 B/second - 19.7 kB/request - 636.704 ms/request 13 requests currently being processed, 0 idle workers CWCCCCCCCWWCW................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-17119931/68/2096C 22.791013907760.70.7937.80 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /server-status HTTP/1.1 1-17120190/62/1792W 17.200011444810.00.4619.56 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.DS_Store HTTP/1.1 2-17119451/65/1507C 21.621010590011.00.3372.06 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /s/39332e3132322e37302e313032/_/;/META-INF/maven/com.atlass 3-17119921/54/1998C 15.231010721850.70.2923.52 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /.git/config HTTP/1.1 4-17120201/61/1737C 17.951010875420.70.9551.85 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /info.php HTTP/1.1 5-17154911/28/1832C 8.011015719080.70.4217.17 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /config.json HTTP/1.1 6-17119941/60/1620C 17.31109744390.90.3778.69 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 7-17120211/63/1614C 17.36108827540.70.9820.43 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /.env HTTP/1.1 8-17119681/71/1640C 21.14108768010.70.6121.97 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /login.action HTTP/1.1 9-17189090/0/1474W 0.00009435370.00.0022.27 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.git/config HTTP/1.1 10-17189100/0/1470W 0.00005695390.00.0013.47 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /.env HTTP/1.1 11-17119441/72/646C 21.58103081860.70.617.24 10.49.100.254http/1.1test.main-vip.de.wolf.eu:80GET /telescope/requests HTTP/1.1 12-17189110/1/856W 0.270010754790.00.0110.42 10.49.100.254http/1.1test.main-vip.de.wolf.eu:443GET /server-status HTTP/1.1 13-15-0/0/390. 0.0012329101796540.00.003.49 10.49.100.254http/1.1wwmaint01.wolf.eu:80GET / HTTP/1.1 14-12-0/0/53. 0.002034030401610.00.001.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 15-12-0/0/15. 0.00201909079370.00.000.04 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 16-13-0/0/254. 0.0013906301851130.00.003.51 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 17-12-0/0/2. 0.00203401000.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 18-12-0/0/1. 0.00203400000.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 19-12-0/0/1. 0.00203399000.00.000.00 127.0.0.1http/1.1wwmaint01.wolf.eu:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 9subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 271 seconds, (range: 265...279)index usage: 0%, cache usage: 0%total entries stored since starting: 62total entries replaced since starting: 0total entries expired since starting: 52total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 144 misstotal removes since starting: 1 hit, 2 miss Apache/2.4.54 (Debian) Server at test.main-vip.de.wolf.eu Port 443
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e073ac091773ac091773ac091773ac091773ac09177
Symfony profiler enabled: https://test.main-vip.de.wolf.eu/_profiler/empty/search/results