The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb312767bdd12767bdd1b5cda127
Apache Status Apache Server Status for www.rbxstock.com (via ::1) Server Version: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28 Server MPM: WinNT Apache Lounge VS16 Server built: Mar 7 2023 13:21:03 Current Time: Wednesday, 26-Jul-2023 01:14:42 Georgian Standard Time Restart Time: Tuesday, 25-Jul-2023 21:03:50 Georgian Standard Time Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 4 hours 10 minutes 52 seconds Server load: -1.00 -1.00 -1.00 Total accesses: 405 - Total Traffic: 8.1 MB - Total Duration: 9252 .0269 requests/sec - 566 B/second - 20.6 kB/request - 22.8444 ms/request 2 requests currently being processed, 148 idle workers ________________________________________________________________ ________________________________________________________________ _____________K_____W__ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMSSReqDurConnChildSlotClientProtocolVHostRequest 0-0112520/4/4_ 460160.00.000.00 ::1http/1.1 0-0112520/1/1_ 465100.00.000.00 ::1http/1.1 0-0112520/2/2_ 46070.00.000.00 ::1http/1.1localhost:8081POST /game/report-event?name=CDNBundleError_unknown_js_Computer 0-0112520/2/2_ 460100.00.000.00 ::1http/1.1localhost:8081POST /game/report-event?name=CDNBundleError_unknown_js_Computer 0-0112520/1/1_ 48360.00.000.00 ::1http/1.1localhost:8081POST /game/report-event?name=JavascriptBundleError_Computer HTT 0-0112520/4/4_ 460120.00.000.00 ::1http/1.1localhost:8081GET /privateJs/ProfileBadges.js HTTP/1.1 0-0112520/1/1_ 487140.00.000.00 ::1http/1.1localhost:8081GET /privateJs/ProfileStatistics.js HTTP/1.1 0-01125210/15/15K 203026.60.010.01 ::1http/1.1localhost:8081GET /config.json HTTP/1.1 0-0112520/2/2_ 460120.00.000.00 ::1http/1.1localhost:8081GET /privateJs/LatencyMeasurement.js HTTP/1.1 0-0112520/2/2_ 48180.00.000.00 ::1http/1.1 0-0112520/4/4_ 481200.00.050.05 ::1http/1.1localhost:8081GET /privateJs/Navigation.js HTTP/1.1 0-0112520/4/4_ 461290.00.010.01 ::1http/1.1 0-0112520/115/115_ 48031190.01.741.74 ::1http/1.1 0-01125214/85/85W 00242825.41.401.40 ::1http/1.1localhost:8081GET /server-status HTTP/1.1 0-0112520/47/47_ 4811570.00.340.34 ::1http/1.1localhost:8081GET /privateJs/CurrentWearing.js HTTP/1.1 0-0112520/116/116_ 48030930.04.584.58 ::1http/1.1localhost:8081GET /universal-app-configuration/v1/behaviors/cookie-policy/con SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28 Server at www.rbxstock.com Port 8081
The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb312767bdd12767bdd1b3c3db12
Apache Status Apache Server Status for www.rbxstock.com (via ::1) Server Version: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28 Server MPM: WinNT Apache Lounge VS16 Server built: Mar 7 2023 13:21:03 Current Time: Wednesday, 26-Jul-2023 01:14:38 Georgian Standard Time Restart Time: Tuesday, 25-Jul-2023 21:03:50 Georgian Standard Time Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 4 hours 10 minutes 48 seconds Server load: -1.00 -1.00 -1.00 Total accesses: 389 - Total Traffic: 8.1 MB - Total Duration: 8601 .0259 requests/sec - 565 B/second - 21.4 kB/request - 22.1105 ms/request 1 requests currently being processed, 149 idle workers ________________________________________________________________ ________________________________________________________________ ___________________W__ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMSSReqDurConnChildSlotClientProtocolVHostRequest 0-0112520/4/4_ 410160.00.000.00 ::1http/1.1 0-0112520/1/1_ 415100.00.000.00 ::1http/1.1 0-0112520/2/2_ 41070.00.000.00 ::1http/1.1localhost:8081POST /game/report-event?name=CDNBundleError_unknown_js_Computer 0-0112520/2/2_ 410100.00.000.00 ::1http/1.1localhost:8081POST /game/report-event?name=CDNBundleError_unknown_js_Computer 0-0112520/1/1_ 43360.00.000.00 ::1http/1.1localhost:8081POST /game/report-event?name=JavascriptBundleError_Computer HTT 0-0112520/4/4_ 410120.00.000.00 ::1http/1.1localhost:8081GET /privateJs/ProfileBadges.js HTTP/1.1 0-0112520/1/1_ 437140.00.000.00 ::1http/1.1localhost:8081GET /privateJs/ProfileStatistics.js HTTP/1.1 0-0112520/5/5_ 361210.00.000.00 ::1http/1.1localhost:8081POST /game/report-event?name=CDNBundleError_unknown_js_Computer 0-0112520/2/2_ 410120.00.000.00 ::1http/1.1localhost:8081GET /privateJs/LatencyMeasurement.js HTTP/1.1 0-0112520/2/2_ 43180.00.000.00 ::1http/1.1 0-0112520/4/4_ 431200.00.050.05 ::1http/1.1localhost:8081GET /privateJs/Navigation.js HTTP/1.1 0-0112520/4/4_ 411290.00.010.01 ::1http/1.1 0-0112520/115/115_ 43031190.01.741.74 ::1http/1.1 0-0112528/79/79W 00205813.11.391.39 ::1http/1.1localhost:8081GET /server-status HTTP/1.1 0-0112520/47/47_ 4311570.00.340.34 ::1http/1.1localhost:8081GET /privateJs/CurrentWearing.js HTTP/1.1 0-0112520/116/116_ 43030930.04.584.58 ::1http/1.1localhost:8081GET /universal-app-configuration/v1/behaviors/cookie-policy/con SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28 Server at www.rbxstock.com Port 8081