The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3172539bea72539bea094a3ce3
Apache Status Apache Server Status for www.sagraconscioit.marcolinmattia.it (via 51.255.51.194) Server Version: Apache/2.4.52 (Ubuntu) OpenSSL/3.0.2 Server MPM: event Server Built: 2023-03-01T22:43:55 Current Time: Saturday, 29-Apr-2023 17:00:46 CEST Restart Time: Thursday, 27-Apr-2023 21:52:59 CEST Parent Server Config. Generation: 4 Parent Server MPM Generation: 3 Server uptime: 1 day 19 hours 7 minutes 47 seconds Server load: 0.06 0.03 0.00 Total accesses: 2556 - Total Traffic: 9.5 MB - Total Duration: 61309 CPU Usage: u3.54 s5.18 cu8.3 cs3 - .0129% CPU load .0165 requests/sec - 64 B/second - 3889 B/request - 23.9863 ms/request 9 requests currently being processed, 41 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 09434no0yes124000 19435no0yes817000 Sum200 941000 ________________________WW_____WWL_C_W_R_____W____.............. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-394340/1/48_ 0.036211308830.00.000.12 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 0-394340/1/44_ 0.00102926112180.00.000.11 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1. 0-394340/1/50_ 0.026211277590.00.000.13 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 0-394340/0/48_ 0.0021719012870.00.000.25 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /.well-known/acme-challenge/pxfO-by6wld3batt9rXIZLDT32j_Jy5 0-394340/0/50_ 0.0062116516640.00.000.15 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /.well-known/acme-challenge/pxfO-by6wld3batt9rXIZLDT32j_Jy5 0-394340/1/45_ 0.0521719317850.00.010.11 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 0-394340/1/49_ 0.055419521430.00.000.15 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /solr/admin/info/system?wt=json HTTP/1.0 0-394340/1/54_ 0.070912710.00.000.14 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /?rest_route=/wp/v2/users/ HTTP/1.0 0-394340/1/47_ 0.07069330.00.000.13 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /.env HTTP/1.0 0-394340/1/50_ 0.0545115660.00.000.13 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /favicon.ico HTTP/1.0 0-394340/1/50_ 0.0345725710.00.000.13 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 0-394340/1/46_ 0.080110160.00.000.24 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /s/439313e21353e2535323e21353/_/;/META-INF/maven/com.atlass 0-394340/1/50_ 0.04231310380.00.000.14 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 0-394340/0/46_ 0.006213157300.00.000.23 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /version HTTP/1.0 0-394340/1/51_ 0.060213180.00.010.14 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 0-394340/0/47_ 0.00110426311030.00.000.14 51.255.51.194http/1.1marcolinmattia.it:7081GET / HTTP/1.0 0-394340/0/49_ 0.00110418615810.00.000.15 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 0-394340/0/46_ 0.0001318360.00.000.12 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /dns-query?dns=ZgcBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE 0-394340/1/48_ 0.1002917960.00.000.13 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /.vscode/sftp.json HTTP/1.0 0-394340/1/49_ 0.090416080.00.010.24 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /server-status HTTP/1.0 0-394340/1/49_ 0.1003310650.00.000.26 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /info.php HTTP/1.0 0-394340/0/49_ 0.001104110210.00.000.24 51.255.51.194http/1.1marcolinmattia.it:7081GET //2019/wp-includes/wlwmanifest.xml HTTP/1.0 0-394340/0/49_ 0.000011430.00.000.15 51.255.51.194http/1.1marcolinmattia.it:7081GET //2021/wp-includes/wlwmanifest.xml HTTP/1.0 0-394340/1/49_ 0.100112870.00.000.14 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /?rest_route=/wp/v2/users/ HTTP/1.0 0-394341/0/50W 0.000015530.00.000.40 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET / HTTP/1.0 1-394351/1/51W 0.010011970.00.000.15 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /server-status HTTP/1.0 1-394350/1/52_ 0.00029890.00.000.27 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 1-394350/1/53_ 0.02460210600.00.000.22 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 1-394350/1/56_ 0.0321717570.00.000.14 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /favicon.ico HTTP/1.0 1-394350/1/50_ 0.0703020350.00.001.19 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /.DS_Store HTTP/1.0 1-394350/1/51_ 0.05012710290.00.000.12 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET / HTTP/1.0 1-394351/0/56W 0.000016510.00.000.27 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /telescope/requests HTTP/1.0 1-394351/0/50W 0.00005620.00.000.12 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 1-394351/1/55L 0.080110210.00.000.14 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /s/439313e21353e2535323e21353/_/;/META-INF/maven/com.atlass 1-394350/1/54_ 0.0445211960.00.000.17 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 1-394350/1/56_ 0.10027060.00.000.14 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /.DS_Store HTTP/1.0 1-394350/1/56_ 0.0472212420.00.000.26 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 1-394351/0/56W 0.000013870.00.000.14 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /telescope/requests HTTP/1.0 1-394350/1/47_ 0.11008030.00.000.11 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /.git/config HTTP/1.0 1-394351/1/54W 0.02009720.00.000.26 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-394350/1/56_ 0.0472116210.00.000.16 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 1-394350/1/50_ 0.11019600.00.000.13 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /.vscode/sftp.json HTTP/1.0 1-394350/1/57_ 0.10075640.00.000.15 51.255.51.194http/1.1www.sagraconscioit.marcolinmattGET /info.php HTTP/1.0 1-394350/1/57_ 0.04612619190.00.010.15 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET / HTTP/1.0 1-394350/0/58_ 0.0009718940.00.000.17 51.255.51.194http/1.1marcolinmattia.it:7081GET /.well-known/acme-challenge/D9GPtbECAuP7Wab6ViYiw0rQLXmyx9D 1-394351/0/55W 0.000015460.00.000.17 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-394350/1/56_ 0.070111550.00.000.14 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /debug/default/view?panel=config HTTP/1.0 1-394350/1/49_ 0.070011900.00.000.12 51.255.51.194http/1.1cmflauncher.marcolinmattia.it:7GET /.git/