Apache 2.4.52
tcp/443
WARNING: This plugin will generate false positive and is purely informative:
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
Severity: info
Fingerprint: 3f43e0ebb5dce37ab8b59eb53ea6237e8f56bf578f56bf578f56bf578f56bf57
Found potentially vulnerable SSH version: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.13 WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31767d2e40767d2e405752e94f
Apache Status Apache Server Status for rocketchat-new.cs.uwaterloo.ca (via 129.97.152.225) Server Version: Apache/2.4.52 (Ubuntu) OpenSSL/3.0.2 Server MPM: event Server Built: 2023-05-03T20:02:51 Current Time: Monday, 06-Nov-2023 22:51:45 UTC Restart Time: Monday, 06-Nov-2023 22:50:00 UTC Parent Server Config. Generation: 5 Parent Server MPM Generation: 4 Server uptime: 1 minute 44 seconds Server load: 0.10 0.08 0.03 Total accesses: 51 - Total Traffic: 73 kB - Total Duration: 4 CPU Usage: u.05 s.01 cu.02 cs.01 - .0865% CPU load .49 requests/sec - 718 B/second - 1465 B/request - .0784314 ms/request 1 requests currently being processed, 49 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 02173no0yes025000 12174no0yes124000 Sum200 149000 ___________________________W______________________.............. ................................................................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-421730/0/1_ 0.0012000.00.000.00 23.178.112.107http/1.1rocketchat-new.cs.uwaterloo.ca:GET /.well-known/acme-challenge/59sMMfUF-WSUjnJsSQxcWVdLzlia7ti 1-421740/1/4_ 0.032000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /.env HTTP/1.1 1-421740/2/2_ 0.032020.00.020.02 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /.DS_Store HTTP/1.1 1-421741/0/2W 0.000000.00.000.00 46.101.103.192http/1.1rocketchat-new.cs.uwaterloo.ca:GET /server-status HTTP/1.1 1-421740/1/1_ 0.002000.00.000.00 46.101.103.192http/1.1 1-421740/0/2_ 0.002000.00.000.00 50.3.85.66http/1.1rocketchat.cs.uwaterloo.ca:443\x16\x03\x01 1-421740/2/2_ 0.031000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /config.json HTTP/1.1 1-421740/1/2_ 0.032000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /.git/config HTTP/1.1 1-421740/2/2_ 0.030000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /_all_dbs HTTP/1.1 1-421740/0/2_ 0.000000.00.000.00 46.101.103.192http/1.1 1-421740/1/1_ 0.040000.00.000.00 46.101.103.192http/1.1rocketchat-new.cs.uwaterloo.ca:GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-421740/1/3_ 0.020000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 1-421740/1/1_ 0.030000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /login.action HTTP/1.1 1-421740/1/1_ 0.031000.00.020.02 46.101.103.192http/1.1rocketchat-new.cs.uwaterloo.ca:GET / HTTP/1.1 1-421740/0/1_ 0.000000.00.000.00 46.101.103.192http/1.1 1-421740/1/3_ 0.020000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /server-status HTTP/1.1 1-421740/1/2_ 0.021000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /v2/_catalog HTTP/1.1 1-421740/1/2_ 0.041000.00.000.00 46.101.103.192http/1.1rocketchat-new.cs.uwaterloo.ca:GET /about HTTP/1.1 1-421740/1/2_ 0.041000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /?rest_route=/wp/v2/users/ HTTP/1.1 1-421740/2/4_ 0.031000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /telescope/requests HTTP/1.1 1-421740/1/3_ 0.031000.00.010.01 46.101.103.192http/1.1rocketchat-new.cs.uwaterloo.ca:GET /.vscode/sftp.json HTTP/1.1 1-421740/1/1_ 0.040000.00.000.00 46.101.103.192http/1.1rocketchat-new.cs.uwaterloo.ca:GET /v2/_catalog HTTP/1.1 1-421740/1/2_ 0.012000.00.000.00 46.101.103.192http/1.1 1-421740/2/3_ 0.031000.00.000.00 139.144.150.23http/1.1rocketchat-new.cs.uwaterloo.ca:GET /s/532323e2235313e27393e2932313/_/;/META-INF/maven/com.atla 1-421740/1/2_ 0.040000.00.000.00 46.101.103.192http/1.1rocketchat-new.cs.uwaterloo.ca:GET /debug/default/view?panel=config HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 11subcaches: 32, indexes per subcache: 88time left on oldest entries' objects: avg: 297 seconds, (range: 295...299)index usage: 0%, cache usage: 0%total entries stored since starting: 11total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 5 hit, 5 misstotal removes since starting: 0 hit, 0 miss Apache/2.4.52 (Ubuntu) Server at rocketchat-new.cs.uwaterloo.ca Port 443
Open service 129.97.152.225:443 · rocketchat.cs.uwaterloo.ca
2026-01-23 06:32
HTTP/1.1 200 OK
Date: Fri, 23 Jan 2026 06:32:05 GMT
Server: Apache/2.4.52 (Ubuntu)
X-XSS-Protection: 1
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Security-Policy: default-src 'self' https://cdn.zapier.com; connect-src *; font-src 'self' https://cdn.zapier.com data:; frame-src *; img-src * data: blob:; media-src * data:; script-src 'self' 'unsafe-eval' 'sha256-jqxtvDkBbRAl9Hpqv68WdNOieepg8tJSYu1xIy7zT34=' 'sha256-aui5xYk3Lu1dQcnsPlNZI+qDTdfzdUv3fzsw80VLJgw=' https://cdn.zapier.com https://zapier.com; style-src 'self' 'unsafe-inline' https://cdn.zapier.com
X-Instance-ID: 0f39f831-36a9-459d-a48b-8ac9d7c86507
Access-Control-Allow-Origin: *
X-Powered-By: Express
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Connection: close
Transfer-Encoding: chunked
Page title: rocketchat.cs
<!DOCTYPE html>
<html>
<head>
<link rel="stylesheet" type="text/css" class="__meteor-css__" href="/e37e3a526aace32e4ea71108fc18652f860ce79f.css?meteor_css_resource=true">
<script id="scripts" type="text/javascript" src="/scripts_887a5339b2625a8970658c4f5f9bd94f1067ab7a.js"></script>
<meta name="referrer" content="same-origin" />
<link rel="icon" sizes="16x16" type="image/png" href=/assets/favicon_16.png />
<link rel="icon" sizes="32x32" type="image/png" href=/assets/favicon_32.png />
<link rel="icon" sizes="any" type="image/svg+xml" href=/assets/favicon.svg />
<title>rocketchat.cs</title><meta name="application-name" content="rocketchat.cs"><meta name="apple-mobile-web-app-title" content="rocketchat.cs">
<meta http-equiv="content-language" content=""><meta name="language" content="">
<meta name="robots" content="INDEX,FOLLOW">
<meta name="msvalidate.01" content="">
<meta name="google-site-verification" content="">
<meta property="fb:app_id" content="">
<base href="/">
</head>
<body>
<noscript style="color: white; text-align:center">
You need to enable JavaScript to run this app.
</noscript>
<div id="react-root">
<div class="page-loading" role="alert" aria-busy="true" aria-live="polite" aria-label="loading">
<div class="loading__animation">
<div class="loading__animation__bounce"></div>
<div class="loading__animation__bounce"></div>
<div class="loading__animation__bounce"></div>
</div>
</div>
</div>
<style id='css-variables'> :root {}</style>
<script type="text/javascript" src="/meteor_runtime_config.js?hash=21828d900ff27b15c1ad7ab0aeec098f547fa62d"></script>
<script type="text/javascript" src="/3054b8907c5ff9acb854316cc540d0d364e126dc.js?meteor_js_resource=true"></script>
</body>
</html>
Open service 129.97.152.225:22
2026-01-22 14:22
Open service 129.97.152.225:443 · rocketchat.cs.uwaterloo.ca
2026-01-09 17:59
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 17:59:07 GMT
Server: Apache/2.4.52 (Ubuntu)
X-XSS-Protection: 1
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Security-Policy: default-src 'self' https://cdn.zapier.com; connect-src *; font-src 'self' https://cdn.zapier.com data:; frame-src *; img-src * data: blob:; media-src * data:; script-src 'self' 'unsafe-eval' 'sha256-jqxtvDkBbRAl9Hpqv68WdNOieepg8tJSYu1xIy7zT34=' 'sha256-aui5xYk3Lu1dQcnsPlNZI+qDTdfzdUv3fzsw80VLJgw=' https://cdn.zapier.com https://zapier.com; style-src 'self' 'unsafe-inline' https://cdn.zapier.com
X-Instance-ID: e0eb6edf-b89c-466d-92f4-cf32d685dbb5
Access-Control-Allow-Origin: *
X-Powered-By: Express
Content-Type: text/html; charset=utf-8
Vary: Accept-Encoding
Connection: close
Transfer-Encoding: chunked
Page title: rocketchat.cs
<!DOCTYPE html>
<html>
<head>
<link rel="stylesheet" type="text/css" class="__meteor-css__" href="/e37e3a526aace32e4ea71108fc18652f860ce79f.css?meteor_css_resource=true">
<script id="scripts" type="text/javascript" src="/scripts_887a5339b2625a8970658c4f5f9bd94f1067ab7a.js"></script>
<meta name="referrer" content="same-origin" />
<link rel="icon" sizes="16x16" type="image/png" href=/assets/favicon_16.png />
<link rel="icon" sizes="32x32" type="image/png" href=/assets/favicon_32.png />
<link rel="icon" sizes="any" type="image/svg+xml" href=/assets/favicon.svg />
<title>rocketchat.cs</title><meta name="application-name" content="rocketchat.cs"><meta name="apple-mobile-web-app-title" content="rocketchat.cs">
<meta http-equiv="content-language" content=""><meta name="language" content="">
<meta name="robots" content="INDEX,FOLLOW">
<meta name="msvalidate.01" content="">
<meta name="google-site-verification" content="">
<meta property="fb:app_id" content="">
<base href="/">
</head>
<body>
<noscript style="color: white; text-align:center">
You need to enable JavaScript to run this app.
</noscript>
<div id="react-root">
<div class="page-loading" role="alert" aria-busy="true" aria-live="polite" aria-label="loading">
<div class="loading__animation">
<div class="loading__animation__bounce"></div>
<div class="loading__animation__bounce"></div>
<div class="loading__animation__bounce"></div>
</div>
</div>
</div>
<style id='css-variables'> :root {}</style>
<script type="text/javascript" src="/meteor_runtime_config.js?hash=21828d900ff27b15c1ad7ab0aeec098f547fa62d"></script>
<script type="text/javascript" src="/3054b8907c5ff9acb854316cc540d0d364e126dc.js?meteor_js_resource=true"></script>
</body>
</html>