The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb3157dfcc7157dfcc71ddfffc0f
Apache Status Apache Server Status for 176.53.182.169 (via 192.168.2.3) Server Version: Apache/2.4.41 (Ubuntu) OpenSSL/1.1.1f Server MPM: event Server Built: 2023-03-08T17:32:54 Current Time: Sunday, 17-Sep-2023 02:08:55 MSK Restart Time: Wednesday, 13-Sep-2023 06:49:46 MSK Parent Server Config. Generation: 5 Parent Server MPM Generation: 4 Server uptime: 3 days 19 hours 19 minutes 8 seconds Server load: 0.00 0.00 0.00 Total accesses: 6136 - Total Traffic: 49.3 MB - Total Duration: 1807584 CPU Usage: u7.7 s13.09 cu25.01 cs6.7 - .016% CPU load .0187 requests/sec - 157 B/second - 8.2 kB/request - 294.587 ms/request 1 requests currently being processed, 49 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 2590989no0yes025000 3590990no0yes124000 Sum200 149000 ..................................................______________ _______________W____________________............................ ...................... Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-3-0/0/104. 0.007732125230540.00.001.17 146.0.32.141http/1.1::1:443GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&co 0-3-0/0/127. 0.0077320440190.00.000.68 207.90.244.6http/1.1 0-3-0/0/111. 0.0077320338060.00.000.42 207.90.244.6http/1.1 0-3-0/0/130. 0.00773288430810.00.000.89 207.90.244.6http/1.1 0-3-0/0/92. 0.007732102227950.00.000.15 146.0.32.141http/1.1::1:443GET /index.php/login HTTP/1.1 0-3-0/0/146. 0.00773297363350.00.000.46 218.32.249.127http/1.1::1:80\x16\x03\x01 0-3-0/0/114. 0.0077320226770.00.000.15 192.241.219.44http/1.1::1:80GET /druid/index.html HTTP/1.1 0-3-0/0/102. 0.0077320240480.00.000.59 207.90.244.6http/1.1 0-3-0/0/131. 0.007732134277360.00.000.65 143.42.22.136http/1.1::1:80\x1b\x84\xd5\xb0]\xf4\xc4\x93\xc50\xc2X\x8c\xda\xb1\xd7\xac\xafn\x1d\xe1\x1e\x1a3*\x85\xb7\x1d'\xb1\xc9k\xbf\xf0\xbc\n 0-3-0/0/95. 0.007732100281950.00.001.03 146.0.32.141http/1.1 0-3-0/0/124. 0.0077320358980.00.000.42 207.90.244.6http/1.1 0-3-0/0/143. 0.0077320300320.00.000.33 109.205.213.94http/1.1::1:80GET / HTTP/1.1 0-3-0/0/100. 0.007732120249030.00.000.14 207.90.244.6http/1.1 0-3-0/0/119. 0.007732108316830.00.000.18 218.32.249.127http/1.1::1:80\x16\x03\x01 0-3-0/0/162. 0.007732108318880.00.000.97 185.216.71.145http/1.1 0-3-0/0/254. 0.007732136555490.00.008.14 52.91.41.184http/1.1::1:443GET / HTTP/1.1 0-3-0/0/126. 0.007732131286500.00.000.25 207.90.244.6http/1.1 0-3-0/0/225. 0.0077320759120.00.003.25 185.216.71.145http/1.1::1:80GET /.env HTTP/1.1 0-3-0/0/124. 0.0077320415810.00.000.17 207.90.244.6http/1.1::1:443\n 0-3-0/0/129. 0.007732133337720.00.000.24 52.91.41.184http/1.1::1:443GET /index.php/login HTTP/1.1 0-3-0/0/119. 0.0077320294060.00.001.56 192.241.219.44http/1.1 0-3-0/0/130. 0.0077320341950.00.000.60 52.91.41.184http/1.1::1:80GET / HTTP/1.1 0-3-0/0/111. 0.0077320289320.00.000.47 179.43.163.130http/1.1::1:80GET / HTTP/1.1 0-3-0/0/100. 0.007732110423510.00.000.22 52.91.41.184http/1.1 0-3-0/0/123. 0.007732131363550.00.000.99 52.91.41.184http/1.1 1-3-0/0/81. 0.007732130169150.00.001.16 207.90.244.6http/1.1 1-3-0/0/129. 0.0077320459300.00.002.26 207.90.244.6http/1.1 1-3-0/0/150. 0.007732117572720.00.001.29 207.90.244.6http/1.1 1-3-0/0/117. 0.007732668323670.00.001.18 207.90.244.6http/1.1::1:443\n 1-3-0/0/150. 0.00773201054660.00.003.36 154.209.125.141http/1.1::1:80GET / HTTP/1.1 1-3-0/0/93. 0.00773266349840.00.000.50 109.237.98.226http/1.1::1:443POST /.env HTTP/1.1 1-3-0/0/102. 0.0077320325310.00.000.30 207.90.244.6h2done, streams: 0/0/0/0/0 (open/recv/resp/push/rst) 1-3-0/0/74. 0.00773293160620.00.000.10 146.0.32.141http/1.1::1:443GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&co 1-3-0/0/116. 0.007732124508660.00.000.39 207.90.244.6h2done, streams: 0/0/0/0/0 (open/recv/resp/push/rst) 1-3-0/0/96. 0.0077320266800.00.000.94 194.180.49.165http/1.1::1:80GET / HTTP/1.1 1-3-0/0/121. 0.007732596784120.00.001.93 154.209.125.141http/1.1 1-3-0/0/178. 0.007732126674620.00.000.86 3.79.29.115http/1.1 1-3-0/0/138. 0.0077320504300.00.000.31 146.0.32.141http/1.1 1-3-0/0/116. 0.007732682328730.00.000.89 109.237.98.226http/1.1 1-3-0/0/105. 0.0077320283320.00.000.40 211.248.4.250http/1.1::1:80GET http://176.53.182.169:80/phpmanager/scripts/setup.php HTTP/ 1-3-0/0/126. 0.007732113308380.00.001.24 146.0.32.141http/1.1::1:443GET /index.php/login HTTP/1.1 1-3-0/0/121. 0.007732136347570.00.001.49 207.90.244.6h2done, streams: 0/0/0/0/0 (open/recv/resp/push/rst) 1-3-0/0/99. 0.0077320227140.00.000.23 207.90.244.6http/1.1 1-3-0/0/100. 0.007732124221480.00.000.93 109.237.98.226http/1.1::1:443GET /index.php/login HTTP/1.1 1-3-0/0/99. 0.007732117164050.00.000.43 109.237.98.226http/1.1 1-3-0/0/84. 0.0077320285020.00.000.16 207.90.244.6http/1.1::1:443GET /core/img/favicon.ico HTTP/1.1 1-3-0/0/101. 0.007732129219780.00.001.06 3.79.29.115http/1.1 1-3-0/0/91. 0.007732115189680.00.000.90 207.90.244.6http/1.1 1-3-0/0/124. 0.007732126334030.00.000.95 207.90.244.6http/1.1::1:443GET /index.php/login HTTP/1.1 1-3-0/0/164. 0.0077320332380.00.001.85 211.248.4.250http/1.1::1:80GET http://176.53.182.169:80/phpMyAdmin-2.10.2/scripts/setup.ph 2-45909890/1/1_ 0.08192920.00.000.00 138.68.163.10http/1.1::1:443GET /.vscode/sftp.json HTTP/1.1 2-45909890/1/1_ 0.011000.00.000.00 167.248.133.127http/1.1::1:80GET / HTTP/1.1 2-45909890/1/1_ 0.09087870.00.000.00 138.68.163.10http/1.1::1:443GET /debug/default/view?panel=config HTTP/1.1 2-45909890/1/1_ 0.0901141140.00.000.00 138.68.163.10http/1.1::1:443GET /v2/_catalog HTTP/1.1 2-45909890/1/1_ 0.010000.00.000.00 167.248.133.127http/1.1::1:80PRI * HTTP/2.0 2-45909890/1/1_ 0.0301231230.0