The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3143efdc9443efdc94dace93f9
Apache Status Apache Server Status for www.test.adyouri.com (via 127.0.0.1) Server Version: Apache/2.4.58 (Ubuntu) Server MPM: event Server Built: 2024-07-17T18:55:23 Current Time: Sunday, 22-Sep-2024 19:33:32 UTC Restart Time: Saturday, 21-Sep-2024 06:28:06 UTC Parent Server Config. Generation: 2 Parent Server MPM Generation: 1 Server uptime: 1 day 13 hours 5 minutes 25 seconds Server load: 0.21 0.05 0.02 Total accesses: 126 - Total Traffic: 279 kB - Total Duration: 100 CPU Usage: u4.22 s7.62 cu.07 cs.12 - .00901% CPU load .000944 requests/sec - 2 B/second - 2267 B/request - .793651 ms/request 1 requests currently being processed, 0 workers gracefully restarting, 49 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusygracefulidlewritingkeep-aliveclosing 044489no0yes0025000 144492no0yes1024000 Sum200 1049000 ______________________________W___________________.............. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-1444890/4/4_ 0.150020.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET /server HTTP/1.1 0-1444890/3/3_ 0.1027579000.00.010.01 172.233.57.157http/1.1 0-1444890/4/4_ 0.160010.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /.vscode/sftp.json HTTP/1.1 0-1444890/6/6_ 0.160010.00.020.02 127.0.0.1http/1.1127.0.1.1:8083GET /about HTTP/1.1 0-1444890/2/2_ 0.160000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /debug/default/view?panel=config HTTP/1.1 0-1444890/4/4_ 0.160010.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET /v2/_catalog HTTP/1.1 0-1444890/2/2_ 0.160110.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/4/4_ 0.1427587000.00.010.01 172.233.57.157http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/4/4_ 0.1327585000.00.010.01 172.233.57.157http/1.1 0-1444890/4/4_ 0.1127582000.00.010.01 172.233.57.157http/1.1 0-1444890/3/3_ 0.1427582010.00.000.00 172.233.57.157http/1.1127.0.1.1:8083\x16\x03\x01\x02 0-1444890/3/3_ 0.1327582030.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /dana-na/nc/nc_gina_ver.txt HTTP/1.1 0-1444890/4/4_ 0.1427581010.00.010.01 172.233.57.157http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/3/3_ 0.1327581000.00.000.00 172.233.57.157http/1.1 0-1444890/3/3_ 0.1421174010.00.000.00 81.17.22.122http/1.1127.0.1.1:8083CONNECT google.com:443 HTTP/1.1 0-1444890/2/2_ 0.1416455120.00.000.00 23.95.200.178http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/2/2_ 0.1321174000.00.000.00 81.17.22.122http/1.1 0-1444890/2/2_ 0.1316455000.00.000.00 23.95.200.178http/1.1 0-1444890/4/4_ 0.141864120.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/4/4_ 0.141864000.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET /icons/ubuntu-logo.png HTTP/1.1 0-1444890/3/3_ 0.141863000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /favicon.ico HTTP/1.1 0-1444890/2/2_ 0.131858000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /geoserver/web/wicket/bookmarkable/org.geoserver.web.AboutG 0-1444890/3/3_ 0.131858110.00.000.00 172.233.57.157http/1.1127.0.1.1:8083\x16\x03\x01\x02 0-1444890/2/2_ 0.150110.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/4/4_ 0.150120.00.020.02 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 1-1444920/2/3_ 0.1100440.00.000.01 127.0.0.1http/1.1127.0.1.1:8083GET /server HTTP/1.1 1-1444920/2/2_ 0.110000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /.vscode/sftp.json HTTP/1.1 1-1444920/3/4_ 0.110030.00.010.02 127.0.0.1http/1.1127.0.1.1:8083GET /about HTTP/1.1 1-1444920/2/2_ 0.110000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /debug/default/view?panel=config HTTP/1.1 1-1444920/1/2_ 0.110040.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /v2/_catalog HTTP/1.1 1-14449219/0/0W 0.000000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /server-status HTTP/1.1 1-1444920/3/4_ 0.110000.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-1444920/2/2_ 0.0927591000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /human.aspx HTTP/1.1 1-1444920/0/1_ 0.0027591000.00.000.00 81.17.22.122http/1.1127.0.1.1:8083CONNECT google.com:443 HTTP/1.1 1-1444920/1/1_ 0.0927590000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /geoserver/index.html HTTP/1.1 1-1444920/2/3_ 0.110020.00.000.01 127.0.0.1http/1.1127.0.1.1:8083GET /telescope/requests HTTP/1.1 1-1444920/2/2_ 0.110110.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /?rest_route=/wp/v2/users/ HTTP/1.1 1-1444920/1/2_ 0.0727590000.00.000.00 80.82.77.202http/1.1127.0.1.1:8083\x16\x03\x01 1-1444920/1/1_ 0.1027581000.00.010.01 172.233.57.157http/1.1127.0.1.1:8083GET / HTTP/1.0 1-1444920/1/2_ 0.110040.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 1-1444920/1/1_ 0.0727581000.00.000.00 80.82.77.202http/1.1127.0.1.1:8083\x16\x03\x01 1-1444920/1/1_ 0.100000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-1444920/2/2_ 0.100330.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /server-status HTTP/1.1 1-1444920/1/1_ 0.100000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /login.action HTTP/1.1 1-1444920/2/2_ 0.100000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /_all_dbs HTTP/1.1 1-1444920/1/1_ 0.100000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /.DS_Store HTTP/1.1 1-1444920/2/2_ 0.110000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /.env HTTP/1.1 1-1444920/2/2_ 0.110000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /.git/config HTTP/1.1 1-1444920/1/1_ 0.110000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /s/0393e2833323e2238313e2930323/_/;/META-INF/maven/com.atla 1-1444920/1/1_ 0.110000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /config.json HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot Apache/2.4.58 (Ubuntu) Server at www.test.adyouri.com Port
The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3143efdc9443efdc94047eff94
Apache Status Apache Server Status for www.test.adyouri.com (via 127.0.0.1) Server Version: Apache/2.4.58 (Ubuntu) Server MPM: event Server Built: 2024-07-17T18:55:23 Current Time: Sunday, 22-Sep-2024 19:33:32 UTC Restart Time: Saturday, 21-Sep-2024 06:28:06 UTC Parent Server Config. Generation: 2 Parent Server MPM Generation: 1 Server uptime: 1 day 13 hours 5 minutes 25 seconds Server load: 0.21 0.05 0.02 Total accesses: 109 - Total Traffic: 258 kB - Total Duration: 93 CPU Usage: u4.21 s7.62 cu.07 cs.12 - .009% CPU load .000816 requests/sec - 1 B/second - 2423 B/request - .853211 ms/request 1 requests currently being processed, 0 workers gracefully restarting, 49 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusygracefulidlewritingkeep-aliveclosing 044489no0yes0025000 144492no0yes1024000 Sum200 1049000 __________________________________________W_______.............. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-1444890/4/4_ 0.150020.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET /server HTTP/1.1 0-1444890/3/3_ 0.1027578000.00.010.01 172.233.57.157http/1.1 0-1444890/4/4_ 0.160010.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /.vscode/sftp.json HTTP/1.1 0-1444890/6/6_ 0.160010.00.020.02 127.0.0.1http/1.1127.0.1.1:8083GET /about HTTP/1.1 0-1444890/2/2_ 0.160000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /debug/default/view?panel=config HTTP/1.1 0-1444890/4/4_ 0.160010.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET /v2/_catalog HTTP/1.1 0-1444890/2/2_ 0.160110.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/4/4_ 0.1427586000.00.010.01 172.233.57.157http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/4/4_ 0.1327584000.00.010.01 172.233.57.157http/1.1 0-1444890/4/4_ 0.1127581000.00.010.01 172.233.57.157http/1.1 0-1444890/3/3_ 0.1427581010.00.000.00 172.233.57.157http/1.1127.0.1.1:8083\x16\x03\x01\x02 0-1444890/3/3_ 0.1327581030.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /dana-na/nc/nc_gina_ver.txt HTTP/1.1 0-1444890/4/4_ 0.1427580010.00.010.01 172.233.57.157http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/3/3_ 0.1327580000.00.000.00 172.233.57.157http/1.1 0-1444890/3/3_ 0.1421174010.00.000.00 81.17.22.122http/1.1127.0.1.1:8083CONNECT google.com:443 HTTP/1.1 0-1444890/2/2_ 0.1416454120.00.000.00 23.95.200.178http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/2/2_ 0.1321174000.00.000.00 81.17.22.122http/1.1 0-1444890/2/2_ 0.1316454000.00.000.00 23.95.200.178http/1.1 0-1444890/4/4_ 0.141863120.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/4/4_ 0.141863000.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET /icons/ubuntu-logo.png HTTP/1.1 0-1444890/3/3_ 0.141863000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /favicon.ico HTTP/1.1 0-1444890/2/2_ 0.131858000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /geoserver/web/wicket/bookmarkable/org.geoserver.web.AboutG 0-1444890/3/3_ 0.131858110.00.000.00 172.233.57.157http/1.1127.0.1.1:8083\x16\x03\x01\x02 0-1444890/2/2_ 0.150110.00.010.01 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 0-1444890/4/4_ 0.150120.00.020.02 127.0.0.1http/1.1127.0.1.1:8083GET / HTTP/1.1 1-1444920/1/2_ 0.072759144440.00.000.01 80.82.77.202http/1.1127.0.1.1:8083\x16\x03\x02\x01o\x01 1-1444920/1/1_ 0.0927591000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /user HTTP/1.1 1-1444920/2/3_ 0.0927591030.00.010.01 172.233.57.157http/1.1127.0.1.1:8083GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1 1-1444920/1/1_ 0.0727591000.00.000.00 80.82.77.202http/1.1127.0.1.1:8083\x16\x03\x01 1-1444920/0/1_ 0.0027591440.00.000.00 115.231.78.15http/1.1127.0.1.1:8083GET /robots.txt HTTP/1.1 1-1444920/2/3_ 0.0927591000.00.010.01 172.233.57.157http/1.1127.0.1.1:8083GET / HTTP/1.1 1-1444920/2/2_ 0.0927591000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /human.aspx HTTP/1.1 1-1444920/0/1_ 0.0027590000.00.000.00 81.17.22.122http/1.1127.0.1.1:8083CONNECT google.com:443 HTTP/1.1 1-1444920/1/1_ 0.0927590000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /geoserver/index.html HTTP/1.1 1-1444920/1/2_ 0.0927591020.00.000.01 172.233.57.157http/1.1127.0.1.1:8083GET /confluence/rest/applinks/1.0/manifest HTTP/1.1 1-1444920/1/1_ 0.0927591000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /Portal0000.htm HTTP/1.1 1-1444920/1/2_ 0.0727590000.00.000.00 80.82.77.202http/1.1127.0.1.1:8083\x16\x03\x01 1-1444920/1/1_ 0.1027580000.00.010.01 172.233.57.157http/1.1127.0.1.1:8083GET / HTTP/1.0 1-1444920/0/1_ 0.0027591330.00.000.00 81.17.22.122http/1.1127.0.1.1:8083CONNECT google.com:443 HTTP/1.1 1-1444920/1/1_ 0.0727580000.00.000.00 80.82.77.202http/1.1127.0.1.1:8083\x16\x03\x01 1-1444920/1/1_ 0.100000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-1444922/1/1W 0.080000.00.000.00 127.0.0.1http/1.1127.0.1.1:8083GET /server-status HTTP/1.1 1-1444920/1/1_ 0.0859870000.00.000.00 81.17.22.122http/1.1127.0.1.1:8083CONNECT google.com:443 HTTP/1.1 1-1444920/1/1_ 0.0827591000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /Portal/Portal.mwsl HTTP/1.1 1-1444920/1/1_ 0.0927591000.00.000.00 172.233.57.157http/1.1127.0.1.1:8083GET /rest/applinks/1.0/manifest HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot Apache/2.4.58 (Ubuntu) Server at www.test.adyouri.com Port 80