Apache 2.4.62
tcp/80
OpenSSL 3.0.8
tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65220d37dc73
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://kupa_cuong-at-997319587654:xhq49ZTXpKyNki%2FwHVOygND9nTb64ns1mtkM4fEUnS0%3D@git-codecommit.ap-northeast-1.amazonaws.com/v1/repos/alinez_front fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [pull] ff = no rebase = false
The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31b47c6615b47c6615e06f6088
Apache Status Apache Server Status for 35.75.223.8 (via 10.80.29.44) Server Version: Apache/2.4.6 (CentOS) Server MPM: prefork Server Built: Apr 24 2019 13:45:48 Current Time: Friday, 27-Oct-2023 00:08:35 JST Restart Time: Sunday, 11-Sep-2022 20:02:49 JST Parent Server Config. Generation: 71 Parent Server MPM Generation: 70 Server uptime: 410 days 4 hours 5 minutes 46 seconds Server load: 0.01 0.04 0.05 Total accesses: 3150120 - Total Traffic: 2.0 GB CPU Usage: u.61 s1.46 cu.95 cs1.12 - 1.17e-5% CPU load .0889 requests/sec - 59 B/second - 671 B/request 4 requests currently being processed, 7 idle workers K__K__W_.K__.................................................... ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqConnChildSlotClientVHostRequest 0-7049091/105/238891K 0.495400.70.04149.88 10.80.29.26any:80HEAD /Core/Skin/Login.aspx HTTP/1.1 1-7091210/6/229066_ 0.13200.00.07145.25 10.80.29.26any:80NULL 2-70128530/2/221051_ 0.0065420.00.00139.24 10.80.28.105any:80GET /healthcheck/check_lamp.php HTTP/1.1 3-703257222/36/215502K 0.161757.60.14135.09 10.80.29.7any:80GET /healthcheck/check.php HTTP/1.1 4-70325730/112/206421_ 0.525600.00.04127.26 10.80.29.26any:80NULL 5-7048900/3/202039_ 0.003200.00.00125.97 10.80.29.7any:80NULL 6-7048913/8/191004W 0.01001.90.00119.82 10.80.29.7any:80GET /server-status HTTP/1.1 7-70325750/13/177874_ 0.01107140.00.01109.88 10.80.29.26any:80NULL 8-70-0/0/174161. 0.0167500.00.00108.71 ::1any:80OPTIONS * HTTP/1.0 9-70489323/30/152984K 0.10648.00.0197.82 10.80.29.26any:80GET /healthcheck/check.php HTTP/1.1 10-70283630/212/147615_ 1.028400.00.1394.17 10.80.29.7any:80NULL 11-7048940/12/130726_ 0.012180.00.0186.08 10.80.29.26any:80NULL 12-70-0/0/116519. 0.6168500.00.0075.62 ::1any:80OPTIONS * HTTP/1.0 13-70-0/0/96687. 0.00244200.00.0063.59 ::1any:80OPTIONS * HTTP/1.0 14-70-0/0/90603. 0.00244100.00.0059.27 ::1any:80OPTIONS * HTTP/1.0 15-70-0/0/87048. 0.00481800.00.0060.10 ::1any:80OPTIONS * HTTP/1.0 16-70-0/0/82548. 0.52487100.00.0054.32 ::1any:80OPTIONS * HTTP/1.0 17-70-0/0/76016. 0.00488200.00.0050.37 ::1any:80OPTIONS * HTTP/1.0 18-70-0/0/66754. 0.00488100.00.0045.55 ::1any:80OPTIONS * HTTP/1.0 19-70-0/0/51521. 0.00488000.00.0035.61 ::1any:80OPTIONS * HTTP/1.0 20-70-0/0/37303. 0.00487900.00.0024.71 ::1any:80OPTIONS * HTTP/1.0 21-70-0/0/30924. 0.00487800.00.0020.97 ::1any:80OPTIONS * HTTP/1.0 22-70-0/0/30822. 0.00487700.00.0019.81 ::1any:80OPTIONS * HTTP/1.0 23-70-0/0/28271. 0.51487300.00.0018.94 ::1any:80OPTIONS * HTTP/1.0 24-70-0/0/24294. 0.00487400.00.0016.10 ::1any:80OPTIONS * HTTP/1.0 25-70-0/0/14184. 0.00487600.00.0010.48 ::1any:80OPTIONS * HTTP/1.0 26-70-0/0/7668. 0.00978300.00.006.35 ::1any:80OPTIONS * HTTP/1.0 27-70-0/0/3776. 0.00988100.00.002.31 ::1any:80OPTIONS * HTTP/1.0 28-70-0/0/2691. 0.00993600.00.002.40 ::1any:80OPTIONS * HTTP/1.0 29-70-0/0/1808. 0.00988000.00.001.32 ::1any:80OPTIONS * HTTP/1.0 30-70-0/0/1258. 0.0017405300.00.000.84 ::1any:80OPTIONS * HTTP/1.0 31-70-0/0/1764. 0.0017405200.00.000.92 ::1any:80OPTIONS * HTTP/1.0 32-70-0/0/2007. 0.0017405100.00.001.18 ::1any:80OPTIONS * HTTP/1.0 33-70-0/0/881. 0.0022412400.00.001.06 ::1any:80OPTIONS * HTTP/1.0 34-70-0/0/1024. 0.0022412300.00.000.93 ::1any:80OPTIONS * HTTP/1.0 35-70-0/0/730. 0.0022412200.00.000.79 ::1any:80OPTIONS * HTTP/1.0 36-70-0/0/809. 0.0022411600.00.000.34 ::1any:80OPTIONS * HTTP/1.0 37-70-0/0/783. 0.0022412100.00.000.57 ::1any:80OPTIONS * HTTP/1.0 38-70-0/0/791. 0.0022412000.00.000.31 ::1any:80OPTIONS * HTTP/1.0 39-70-0/0/1264. 0.0022411900.00.000.69 ::1any:80OPTIONS * HTTP/1.0 40-70-0/0/561. 0.0022411800.00.000.40 ::1any:80OPTIONS * HTTP/1.0 41-70-0/0/587. 0.0022411700.00.000.30 ::1any:80OPTIONS * HTTP/1.0 42-69-0/0/823. 0.0042189500.00.000.59 ::1any:80OPTIONS * HTTP/1.0 43-63-0/0/16. 0.04461517700.00.000.01 ::1any:80OPTIONS * HTTP/1.0 44-57-0/0/18. 0.00816748300.00.000.04 ::1any:80OPTIONS * HTTP/1.0 45-44-0/0/23. 0.001418442100.00.000.07 ::1any:80OPTIONS * HTTP/1.0 46-44-0/0/3. 0.001418442000.00.000.00 ::1any:80OPTIONS * HTTP/1.0 47-44-0/0/2. 0.001418441900.00.000.00 ::1any:80OPTIONS * HTTP/1.0 48-40-0/0/1. 0.001593008100.00.000.00 ::1any:80OPTIONS * HTTP/1.0 49-40-0/0/1. 0.001593008000.00.000.00 ::1any:80OPTIONS * HTTP/1.0 50-40-0/0/1. 0.001593007900.00.000.00 ::1any:80OPTIONS * HTTP/1.0 51-40-0/0/1. 0.001593007800.00.000.00 ::1any:80OPTIONS * HTTP/1.0 52-40-0/0/1. 0.001593007700.00.000.00 ::1any:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31b47c6615b47c66155e00ff06
Apache Status Apache Server Status for 35.75.223.8 (via 10.80.29.44) Server Version: Apache/2.4.6 (CentOS) Server MPM: prefork Server Built: Apr 24 2019 13:45:48 Current Time: Tuesday, 24-Oct-2023 10:13:49 JST Restart Time: Sunday, 11-Sep-2022 20:02:49 JST Parent Server Config. Generation: 71 Parent Server MPM Generation: 70 Server uptime: 407 days 14 hours 11 minutes Server load: 0.01 0.03 0.05 Total accesses: 3130543 - Total Traffic: 2.0 GB CPU Usage: u.74 s.85 cu.57 cs.64 - 7.95e-6% CPU load .0889 requests/sec - 59 B/second - 671 B/request 3 requests currently being processed, 9 idle workers .W_.K_..____K___................................................ ................................................................ ................................................................ ................................................................ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqConnChildSlotClientVHostRequest 0-70-0/0/236986. 0.0086900.00.00148.90 ::1any:80OPTIONS * HTTP/1.0 1-7081823/9/227698W 0.16001.90.10144.42 10.80.29.7any:80GET /server-status HTTP/1.1 2-7081830/3/220338_ 0.004200.00.00138.91 10.80.29.7any:80NULL 3-70-0/0/214665. 0.1087100.00.00134.23 ::1any:80OPTIONS * HTTP/1.0 4-70999767/287/205217K 1.3719623.20.10126.72 10.80.29.26any:80GET /healthcheck/check.php HTTP/1.1 5-7081840/1/200718_ 0.0078200.00.00125.12 10.80.28.105any:80GET /healthcheck/check_lamp.php HTTP/1.1 6-70-0/0/190174. 0.0086300.00.00119.41 ::1any:80OPTIONS * HTTP/1.0 7-70-0/0/176700. 0.0087000.00.00109.17 ::1any:80OPTIONS * HTTP/1.0 8-7087090/3/172958_ 0.0014500.00.00108.12 10.80.29.7any:80NULL 9-7087100/3/152056_ 0.122300.00.0797.28 10.80.29.26any:80NULL 10-7084680/0/146793_ 0.007500.00.0093.64 10.80.29.26any:80NULL 11-7087210/0/129898_ 0.009400.00.0085.47 10.80.29.7any:80NULL 12-702155167/177/115506K 0.851423.20.0675.09 10.80.29.7any:80GET /healthcheck/check.php HTTP/1.1 13-7081260/4/96032_ 0.121961420.00.0763.24 10.80.29.7any:80NULL 14-7087220/2/90152_ 0.0017700.00.0059.04 10.80.29.26any:80NULL 15-7081280/2/86517_ 0.0412600.00.0459.73 10.80.29.26any:80NULL 16-70-0/0/81907. 0.00115700.00.0054.07 ::1any:80OPTIONS * HTTP/1.0 17-70-0/0/75624. 0.00115800.00.0050.21 ::1any:80OPTIONS * HTTP/1.0 18-70-0/0/66434. 0.00115500.00.0045.38 ::1any:80OPTIONS * HTTP/1.0 19-70-0/0/50521. 0.00115300.00.0035.22 ::1any:80OPTIONS * HTTP/1.0 20-70-0/0/37263. 0.00115400.00.0024.67 ::1any:80OPTIONS * HTTP/1.0 21-70-0/0/30821. 0.00115600.00.0020.88 ::1any:80OPTIONS * HTTP/1.0 22-70-0/0/30446. 0.00116500.00.0019.58 ::1any:80OPTIONS * HTTP/1.0 23-70-0/0/27891. 0.00116400.00.0018.71 ::1any:80OPTIONS * HTTP/1.0 24-70-0/0/23911. 0.00116300.00.0015.89 ::1any:80OPTIONS * HTTP/1.0 25-70-0/0/14050. 0.00116200.00.0010.43 ::1any:80OPTIONS * HTTP/1.0 26-70-0/0/7655. 0.00116100.00.006.35 ::1any:80OPTIONS * HTTP/1.0 27-70-0/0/3773. 0.00116000.00.002.31 ::1any:80OPTIONS * HTTP/1.0 28-70-0/0/2688. 0.00115900.00.002.40 ::1any:80OPTIONS * HTTP/1.0 29-70-0/0/1805. 0.00124400.00.001.32 ::1any:80OPTIONS * HTTP/1.0 30-70-0/0/1257. 0.00124300.00.000.84 ::1any:80OPTIONS * HTTP/1.0 31-70-0/0/1763. 0.00124200.00.000.92 ::1any:80OPTIONS * HTTP/1.0 32-70-0/0/2006. 0.00123800.00.001.18 ::1any:80OPTIONS * HTTP/1.0 33-70-0/0/881. 0.00123700.00.001.06 ::1any:80OPTIONS * HTTP/1.0 34-70-0/0/1024. 0.00123600.00.000.93 ::1any:80OPTIONS * HTTP/1.0 35-70-0/0/730. 0.00123500.00.000.79 ::1any:80OPTIONS * HTTP/1.0 36-70-0/0/809. 0.00122900.00.000.34 ::1any:80OPTIONS * HTTP/1.0 37-70-0/0/783. 0.00123400.00.000.57 ::1any:80OPTIONS * HTTP/1.0 38-70-0/0/791. 0.00123300.00.000.31 ::1any:80OPTIONS * HTTP/1.0 39-70-0/0/1264. 0.00123200.00.000.69 ::1any:80OPTIONS * HTTP/1.0 40-70-0/0/561. 0.00123100.00.000.40 ::1any:80OPTIONS * HTTP/1.0 41-70-0/0/587. 0.00123000.00.000.30 ::1any:80OPTIONS * HTTP/1.0 42-69-0/0/823. 0.0019900900.00.000.59 ::1any:80OPTIONS * HTTP/1.0 43-63-0/0/16. 0.04439229100.00.000.01 ::1any:80OPTIONS * HTTP/1.0 44-57-0/0/18. 0.00794459600.00.000.04 ::1any:80OPTIONS * HTTP/1.0 45-44-0/0/23. 0.001396153500.00.000.07 ::1any:80OPTIONS * HTTP/1.0 46-44-0/0/3. 0.001396153400.00.000.00 ::1any:80OPTIONS * HTTP/1.0 47-44-0/0/2. 0.001396153300.00.000.00 ::1any:80OPTIONS * HTTP/1.0 48-40-0/0/1. 0.001570719400.00.000.00 ::1any:80OPTIONS * HTTP/1.0 49-40-0/0/1. 0.001570719300.00.000.00 ::1any:80OPTIONS * HTTP/1.0 50-40-0/0/1. 0.001570719200.00.000.00 ::1any:80OPTIONS * HTTP/1.0 51-40-0/0/1. 0.001570719100.00.000.00 ::1any:80OPTIONS * HTTP/1.0 52-40-0/0/1. 0.001570719000.00.000.00 ::1any:80OPTIONS * HTTP/1.0 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation CPUCPU usage, number of seconds SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot
Open service 35.75.223.8:80
2024-11-19 22:52
HTTP/1.1 302 Found Date: Tue, 19 Nov 2024 22:52:12 GMT Server: Apache/2.4.62 (Amazon Linux) OpenSSL/3.0.8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: PHPSESSID=064jf99i1rsfnp6u99mdtgh74a; path=/; domain=alinez.net Location: /login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.75.223.8:80
2024-11-17 22:40
HTTP/1.1 302 Found Date: Sun, 17 Nov 2024 22:40:30 GMT Server: Apache/2.4.62 (Amazon Linux) OpenSSL/3.0.8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: PHPSESSID=8th19emkmbcc8bhbvbioeoje0s; path=/; domain=alinez.net Location: /login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.75.223.8:80
2024-11-01 22:48
HTTP/1.1 302 Found Date: Fri, 01 Nov 2024 22:48:48 GMT Server: Apache/2.4.62 (Amazon Linux) OpenSSL/3.0.8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: PHPSESSID=08p756hv4u7578lhpdgqdbbisg; path=/; domain=alinez.net Location: /login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.75.223.8:80
2024-10-31 22:55
HTTP/1.1 302 Found Date: Thu, 31 Oct 2024 22:55:25 GMT Server: Apache/2.4.62 (Amazon Linux) OpenSSL/3.0.8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: PHPSESSID=gchj3qvksdtp538siul411971r; path=/; domain=alinez.net Location: /login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.75.223.8:80
2024-10-29 21:39
HTTP/1.1 302 Found Date: Tue, 29 Oct 2024 21:39:47 GMT Server: Apache/2.4.62 (Amazon Linux) OpenSSL/3.0.8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: PHPSESSID=d3cle84f6d3te4tad6705mufm5; path=/; domain=alinez.net Location: /login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.75.223.8:80
2024-10-21 22:47
HTTP/1.1 302 Found Date: Mon, 21 Oct 2024 22:47:07 GMT Server: Apache/2.4.62 (Amazon Linux) OpenSSL/3.0.8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: PHPSESSID=9fe1toas52be3460rgecaa826g; path=/; domain=alinez.net Location: /login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.75.223.8:80
2024-10-19 22:42
HTTP/1.1 302 Found Date: Sat, 19 Oct 2024 22:42:20 GMT Server: Apache/2.4.62 (Amazon Linux) OpenSSL/3.0.8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Set-Cookie: PHPSESSID=tt99fqg0auia0biclbcf8ag73d; path=/; domain=alinez.net Location: /login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8