The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3168db838368db83830af39d58
Apache Status Apache Server Status for xaasbuilder.com (via 103.186.101.162) Server Version: Apache/2.4.29 (Ubuntu) mod_fcgid/2.3.9 OpenSSL/1.1.1 Server MPM: prefork Server Built: 2022-06-23T12:51:37 Current Time: Saturday, 17-Dec-2022 05:57:55 +07 Restart Time: Monday, 28-Nov-2022 15:07:03 +07 Parent Server Config. Generation: 125 Parent Server MPM Generation: 124 Server uptime: 18 days 14 hours 50 minutes 52 seconds Server load: 1.25 1.41 1.36 Total accesses: 708677 - Total Traffic: 7.6 GB CPU Usage: u1115.93 s1095 cu0 cs0 - .137% CPU load .441 requests/sec - 5054 B/second - 11.2 kB/request 1 requests currently being processed, 9 idle workers _._______W_..................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqConnChildSlotClientProtocolVHostRequest 0-124226510/821/72314_ 51.35030.05.07769.14 2a03:b0c0:1:d0::ce9:7001http/1.1sv03.congdulieu.com:8080GET / HTTP/1.0 1-124-0/0/67475. 0.1691321300.00.00719.77 103.186.101.162http/1.1 2-124226590/820/70286_ 42.79010.07.64741.05 2a03:b0c0:1:d0::ce9:7001http/1.1sv03.congdulieu.com:8080GET / HTTP/1.0 3-124226550/813/63903_ 49.62000.04.62734.13 139.144.188.49http/1.1sv03.congdulieu.com:8080GET / HTTP/1.0 4-124226560/816/67865_ 45.88000.04.69729.79 139.144.188.49http/1.1sv03.congdulieu.com:8080GET /info.php HTTP/1.0 5-124226580/818/62821_ 51.49000.05.03643.66 2a03:b0c0:1:d0::ce9:7001http/1.1sv03.congdulieu.com:8080GET / HTTP/1.0 6-124237380/805/50712_ 46.70000.04.67606.66 139.144.188.49http/1.1sv03.congdulieu.com:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 7-124237400/792/69357_ 45.99300.04.71745.35 178.62.221.40http/1.1sv03.congdulieu.com:8080GET /v2/_catalog HTTP/1.0 8-124237430/800/53921_ 39.69000.04.70511.40 139.144.188.49http/1.1sv03.congdulieu.com:8080GET /.env HTTP/1.0 9-124237450/789/57243W 56.65000.06.06552.09 139.144.188.49http/1.1sv03.congdulieu.com:8080GET /server-status HTTP/1.0 10-124237470/796/23413_ 50.48000.04.92241.11 2a03:b0c0:1:d0::ce9:7001http/1.1sv03.congdulieu.com:8080GET / HTTP/1.0 11-114-0/0/29147. 220.1663072540.00.00271.57 103.186.101.162http/1.1 12-113-0/0/2239. 0.831228171850.00.0039.34 103.186.101.162http/1.1 13-78-0/0/823. 47.096389406830.00.0021.15 103.186.101.162http/1.1 14-78-0/0/301. 22.7863892549740.00.0015.66 103.186.101.162http/1.1 15-78-0/0/90. 2.626389428490.00.0011.21 103.186.101.162http/1.1 16-78-0/0/606. 26.9263895912820.00.0016.05 103.186.101.162http/1.1 17-78-0/0/390. 48.716389346660.00.0017.78 103.186.101.162http/1.1 18-86-0/0/6143. 0.0232493400.00.00109.84 185.3.94.68http/1.1travietjapan.com:8080GET /server-status HTTP/1.0 19-78-0/0/47. 4.456389396860.00.006.51 103.186.101.162http/1.1 20-78-0/0/1614. 264.985692534580.00.0036.38 103.186.101.162http/1.1 21-78-0/0/1137. 177.726009834610.00.0023.77 103.186.101.162http/1.1 22-78-0/0/63. 24.246389286090.00.009.30 103.186.101.162http/1.1 23-79-0/0/4057. 319.90438457780.00.0089.71 103.186.101.162http/1.1 24-78-0/0/78. 10.956389318920.00.0011.61 103.186.101.162http/1.1 25-78-0/0/68. 35.7463892667300.00.009.84 103.186.101.162http/1.1 26-78-0/0/76. 46.196389307080.00.0010.89 103.186.101.162http/1.1 27-78-0/0/2414. 444.12516767130.00.0049.25 128.14.134.134http/1.1sv03.congdulieu.com:8443GET / HTTP/1.0 28-78-0/0/53. 19.256389356640.00.007.58 103.186.101.162http/1.1 29-78-0/0/5. 1.636389688620.00.000.81 103.186.101.162http/1.1 30-78-0/0/16. 11.836389326900.00.002.25 103.186.101.162http/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot mod_fcgid status: Total FastCGI processes: 0 SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3168db838368db838340db22fb
Apache Status Apache Server Status for xaasbuilder.com (via 103.186.101.162) Server Version: Apache/2.4.29 (Ubuntu) mod_fcgid/2.3.9 OpenSSL/1.1.1 Server MPM: prefork Server Built: 2022-06-23T12:51:37 Current Time: Saturday, 17-Dec-2022 05:57:51 +07 Restart Time: Monday, 28-Nov-2022 15:07:03 +07 Parent Server Config. Generation: 125 Parent Server MPM Generation: 124 Server uptime: 18 days 14 hours 50 minutes 48 seconds Server load: 1.27 1.42 1.37 Total accesses: 708657 - Total Traffic: 7.6 GB CPU Usage: u1115.92 s1095 cu0 cs0 - .137% CPU load .441 requests/sec - 5054 B/second - 11.2 kB/request 6 requests currently being processed, 4 idle workers _.W_C_LWCL_..................................................... ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqConnChildSlotClientProtocolVHostRequest 0-124226510/819/72312_ 51.35010.05.07769.14 178.62.221.40http/1.1sv03.congdulieu.com:8080GET /?rest_route=/wp/v2/users/ HTTP/1.0 1-124-0/0/67475. 0.1691281300.00.00719.77 103.186.101.162http/1.1 2-124226590/818/70284W 42.79000.07.63741.05 178.62.221.40http/1.1sv03.congdulieu.com:8080GET /server-status HTTP/1.0 3-124226550/811/63901_ 49.622440.04.62734.13 157.90.181.222http/1.1nhuongquyenthuongmai.com:8443GET /latest-quizzes/7 HTTP/1.0 4-124226561/814/67863C 45.88002.04.68729.78 178.62.221.40http/1.1sv03.congdulieu.com:8080GET /.git/config HTTP/1.0 5-124226580/816/62819_ 51.49070.05.03643.65 178.62.221.40http/1.1sv03.congdulieu.com:8080GET / HTTP/1.0 6-124237381/803/50710C 46.70002.14.66606.66 178.62.221.40http/1.1sv03.congdulieu.com:8080GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 7-124237400/790/69355W 45.99000.04.71745.34 178.62.221.40http/1.1sv03.congdulieu.com:8080GET /.env HTTP/1.0 8-124237431/798/53919C 39.69002.14.69511.40 178.62.221.40http/1.1sv03.congdulieu.com:8080GET /s/4373e29373e21323e2430313/_/;/META-INF/maven/com.atlassia 9-124237451/788/57242C 56.65002.06.06552.09 178.62.221.40http/1.1sv03.congdulieu.com:8080GET /.DS_Store HTTP/1.0 10-124237470/794/23411_ 50.47719620.04.92241.11 157.55.39.212http/1.1luatbacbo.vn:8080GET /2020/11/12/ HTTP/1.0 11-114-0/0/29147. 220.1663068540.00.00271.57 103.186.101.162http/1.1 12-113-0/0/2239. 0.831228131850.00.0039.34 103.186.101.162http/1.1 13-78-0/0/823. 47.096389366830.00.0021.15 103.186.101.162http/1.1 14-78-0/0/301. 22.7863892149740.00.0015.66 103.186.101.162http/1.1 15-78-0/0/90. 2.626389388490.00.0011.21 103.186.101.162http/1.1 16-78-0/0/606. 26.9263895512820.00.0016.05 103.186.101.162http/1.1 17-78-0/0/390. 48.716389306660.00.0017.78 103.186.101.162http/1.1 18-86-0/0/6143. 0.0232493000.00.00109.84 185.3.94.68http/1.1travietjapan.com:8080GET /server-status HTTP/1.0 19-78-0/0/47. 4.456389356860.00.006.51 103.186.101.162http/1.1 20-78-0/0/1614. 264.985692494580.00.0036.38 103.186.101.162http/1.1 21-78-0/0/1137. 177.726009794610.00.0023.77 103.186.101.162http/1.1 22-78-0/0/63. 24.246389246090.00.009.30 103.186.101.162http/1.1 23-79-0/0/4057. 319.90438453780.00.0089.71 103.186.101.162http/1.1 24-78-0/0/78. 10.956389278920.00.0011.61 103.186.101.162http/1.1 25-78-0/0/68. 35.7463892267300.00.009.84 103.186.101.162http/1.1 26-78-0/0/76. 46.196389267080.00.0010.89 103.186.101.162http/1.1 27-78-0/0/2414. 444.12516763130.00.0049.25 128.14.134.134http/1.1sv03.congdulieu.com:8443GET / HTTP/1.0 28-78-0/0/53. 19.256389316640.00.007.58 103.186.101.162http/1.1 29-78-0/0/5. 1.636389648620.00.000.81 103.186.101.162http/1.1 30-78-0/0/16. 11.836389286900.00.002.25 103.186.101.162http/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot mod_fcgid status: Total FastCGI processes: 0 SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss