The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31dc062d3ddc062d3d5a04d0e8
Apache Status Apache Server Status for 190.6.178.10 (via 192.168.1.53) Server Version: Apache/2.4.41 (Win64) OpenSSL/1.1.1c PHP/7.2.28 Server MPM: WinNT Apache Lounge VC15 Server built: Aug 11 2019 12:20:04 Current Time: Saturday, 10-Dec-2022 21:59:09 Hora est. Pac�fico, Sudam�rica Restart Time: Tuesday, 11-Oct-2022 10:36:41 Hora est. Pac�fico, Sudam�rica Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 60 days 11 hours 22 minutes 27 seconds Server load: -1.00 -1.00 -1.00 Total accesses: 598 - Total Traffic: 19.3 MB - Total Duration: 1090440 .000114 requests/sec - 3 B/second - 33.1 kB/request - 1823.48 ms/request 2 requests currently being processed, 148 idle workers ________________________________________________________________ ________________________________________________________________ __________W______W____ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMSSReqDurConnChildSlotClientProtocolVHostRequest 0-085120/3/3_ 380198102190.00.030.03 192.168.12.117http/1.1www.example.com:443GET /favicon.ico HTTP/1.1 0-085120/0/0W 01472880400.00.000.00 192.168.3.254http/1.1localhost:8078GET /server-status HTTP/1.1 0-085120/1/1_ 3982614969920.00.000.00 192.168.3.254http/1.1localhost:8078GET /.DS_Store HTTP/1.1 0-085120/13/13_ 398259202420.00.740.74 192.168.3.254http/1.1localhost:8078GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-085120/92/92_ 39825915150660.03.003.00 192.168.3.254http/1.1localhost:8078GET /.env HTTP/1.1 0-085120/32/32_ 3982613456030.00.980.98 192.168.3.254http/1.1localhost:8078GET /api/search?folderIds=0 HTTP/1.1 0-085120/19/19_ 3982597322650.00.560.56 192.168.3.254http/1.1localhost:8078GET /config.json HTTP/1.1 0-085120/21/21_ 39825948290950.01.781.78 192.168.3.254http/1.1localhost:8078GET /.git/config HTTP/1.1 0-085120/74/74W 001819650.01.031.03 192.168.3.254http/1.1localhost:8078GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-085120/49/49_ 39825931809150.03.913.91 192.168.3.254http/1.1localhost:8078GET /telescope/requests HTTP/1.1 0-085120/99/99_ 39826103592160.02.292.29 192.168.3.254http/1.1localhost:8078GET /v2/_catalog HTTP/1.1 0-085120/121/121_ 38020522289860.03.963.96 192.168.12.117http/1.1 0-085120/74/74_ 398259781158720.01.031.03 192.168.3.254http/1.1localhost:8078GET /info.php HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 686total entries replaced since starting: 0total entries expired since starting: 685total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 1 hit, 0 miss Apache/2.4.41 (Win64) OpenSSL/1.1.1c PHP/7.2.28 Server at 190.6.178.10 Port 8078
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31dc062d3ddc062d3d20f1499a
Apache Status Apache Server Status for 190.6.178.10 (via 192.168.1.53) Server Version: Apache/2.4.41 (Win64) OpenSSL/1.1.1c PHP/7.2.28 Server MPM: WinNT Apache Lounge VC15 Server built: Aug 11 2019 12:20:04 Current Time: Tuesday, 06-Dec-2022 07:21:27 Hora est. Pac�fico, Sudam�rica Restart Time: Tuesday, 11-Oct-2022 10:36:41 Hora est. Pac�fico, Sudam�rica Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 55 days 20 hours 44 minutes 45 seconds Server load: -1.00 -1.00 -1.00 Total accesses: 568 - Total Traffic: 19.2 MB - Total Duration: 1087836 .000118 requests/sec - 4 B/second - 34.5 kB/request - 1915.2 ms/request 12 requests currently being processed, 138 idle workers ________________________________________________________________ ________________________________________________________________ __________RWCCWWCRCCCC Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMSSReqDurConnChildSlotClientProtocolVHostRequest 0-085120/0/0R 4826685000.00.000.00 192.168.3.254http/1.1 0-085120/0/0W 041299090100.00.000.00 192.168.3.254http/1.1localhost:8078GET /.DS_Store HTTP/1.1 0-085121/13/13C 0202420.00.740.74 192.168.3.254http/1.1localhost:8078GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-085121/92/92C 015150660.03.003.00 192.168.3.254http/1.1localhost:8078GET /.env HTTP/1.1 0-085120/30/30W 01372016481453970.00.980.98 192.168.3.254http/1.1localhost:8078GET /server-status HTTP/1.1 0-085120/17/17W 01372018922318300.00.560.56 192.168.3.254http/1.1localhost:8078GET / HTTP/1.1 0-085121/21/21C 048290950.01.781.78 192.168.3.254http/1.1localhost:8078GET /.git/config HTTP/1.1 0-085120/54/54R 96626501812210.00.900.90 192.168.3.254http/1.1 0-085121/49/49C 031809150.03.913.91 192.168.3.254http/1.1localhost:8078GET /telescope/requests HTTP/1.1 0-085120/98/98_ 0203592140.02.292.29 192.168.3.254http/1.1localhost:8078GET /debug/default/view?panel=config HTTP/1.1 0-085120/120/120_ 002289800.03.963.96 192.168.3.254http/1.1localhost:8078GET /?rest_route=/wp/v2/users/ HTTP/1.1 0-085121/74/74C 0781158720.01.031.03 192.168.3.254http/1.1localhost:8078GET /info.php HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request DurSum of milliseconds required to process all requests ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 620total entries replaced since starting: 0total entries expired since starting: 619total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 1 hit, 0 miss Apache/2.4.41 (Win64) OpenSSL/1.1.1c PHP/7.2.28 Server at 190.6.178.10 Port 8078