The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65224d009b4d
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@git.assembla.com:soko-media.apppromotionsummit.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The server-status page (usually /server-status) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31350f87f6350f87f6b9b94706
Apache Status Apache Server Status for 52.56.202.188 (via 127.0.0.1) Server Version: Apache/2.4.41 (Ubuntu) mod_fcgid/2.3.9 Server MPM: event Server Built: 2023-03-08T17:32:54 Current Time: Thursday, 26-Oct-2023 14:59:50 BST Restart Time: Tuesday, 10-Oct-2023 18:19:51 BST Parent Server Config. Generation: 17 Parent Server MPM Generation: 16 Server uptime: 15 days 20 hours 39 minutes 58 seconds Server load: 1.20 1.37 1.44 Total accesses: 3479887 - Total Traffic: 76.8 GB - Total Duration: 4058731205 CPU Usage: u946.84 s189.56 cu9357.73 cs1590.14 - .882% CPU load 2.54 requests/sec - 58.8 kB/second - 23.1 kB/request - 1166.34 ms/request 2 requests currently being processed, 74 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 02024277no1yes025000 32024393no2yes025020 42021153no0yes124000 51734191no (old gen)1yes124000 Sum404 298020 _________________________....................................... ...........____________________________________W________________ ______________W_______ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-1620242770/317/31347_ 25.6857616370516930.07.44680.91 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ad-fraud/ad-fraud/mobile-ad-network/social/mob 0-1620242770/317/31354_ 25.6611515353838950.06.46715.94 127.0.0.1http/1.1www.businessofapps.com:8080POST /wp-admin/admin-ajax.php HTTP/1.1 0-1620242770/311/31359_ 25.66411192374485360.06.72757.13 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/ssp/ HTTP/1.1 0-1620242770/317/31453_ 25.6762652353395730.09.24663.26 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ad-servers/ssp/ssp/ssp/app-installs/ad-servers 0-1620242770/309/31333_ 25.66411217348791630.08.47725.07 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/mobile-dsp/mobile-dsp/ssp/mobile-dsp/ad-server 0-1620242770/310/31397_ 25.7216626358072670.07.71711.20 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/influencer-marketing/we%20manage%20digital-fir 0-1620242770/307/31334_ 25.7146623365968760.08.55682.08 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ssp/mobile-ad-network/ad-fraud/app-installs/mo 0-1620242770/319/31273_ 25.6763620352378350.07.22733.53 127.0.0.1http/1.1www.businessofapps.com:8080GET /app-developers/compare/html5/ios/android/ios/html5/mobile- 0-1620242770/318/31347_ 25.6360999376830460.07.02814.23 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/smarthub/ HTTP/1.1 0-1620242770/313/31280_ 25.6860523360484280.09.31662.57 127.0.0.1http/1.1www.businessofapps.com:8080POST /wp-admin/admin-ajax.php HTTP/1.1 0-1620242770/304/31220_ 25.6860513365809450.05.98811.28 127.0.0.1http/1.1www.businessofapps.com:8080POST /wp-admin/admin-ajax.php HTTP/1.1 0-1620242770/304/31269_ 25.6760620358027860.06.76704.24 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ad-servers/ssp/ssp/ssp/ad-fraud/mobile-dsp/ret 0-1620242770/312/31375_ 25.6459609350405620.07.06722.51 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ad-fraud/social/ssp/mobile-dsp/mobile-ad-netwo 0-1620242770/313/31282_ 25.6762534349337530.08.25735.69 127.0.0.1http/1.1www.businessofapps.com:8080POST /wp-admin/admin-ajax.php HTTP/1.1 0-1620242770/311/31350_ 25.6859212348331260.08.05669.63 127.0.0.1http/1.1www.businessofapps.com:8080GET /news/education-app-classdojo-closes-35m-series-c-round/ HT 0-1620242770/320/31434_ 25.7147636351029420.07.67678.68 127.0.0.1http/1.1www.businessofapps.com:8080GET /news/airship-acquires-gummicube-to-bolster-app-store-optim 0-1620242770/308/31295_ 25.6956644373551410.06.49722.48 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ssp/retargeting/retargeting/mobile-ad-analytic 0-1620242770/322/31251_ 25.6859527372046330.013.38702.16 127.0.0.1http/1.1www.businessofapps.com:8080POST /wp-admin/admin-ajax.php HTTP/1.1 0-1620242770/311/31223_ 25.6611795360771890.07.54722.60 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ssp/ssp/mobile-dsp/retargeting/app-installs/ad 0-1620242770/310/31329_ 25.7050649358647820.06.77671.14 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ad-servers/ssp/ssp/ssp/ad-fraud/app-installs/s 0-1620242770/321/31253_ 25.6761543359181430.09.93667.70 127.0.0.1http/1.1www.businessofapps.com:8080POST /wp-admin/admin-ajax.php HTTP/1.1 0-1620242770/309/31339_ 25.59641346359567420.08.31714.32 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/cpc/research/cpc-rates/ HTTP/1.1 0-1620242770/301/31297_ 25.70515198364223430.06.91673.41 127.0.0.1http/1.1www.businessofapps.com:8080GET /data/airbnb-statistics/ HTTP/1.1 0-1620242770/318/31141_ 25.71491420352193270.06.53673.60 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/research/mobile-app-advertising-cpm-rates/ HTTP/1.1 0-1620242770/302/31274_ 25.6762535359936250.06.49772.31 127.0.0.1http/1.1www.businessofapps.com:8080POST /wp-admin/admin-ajax.php HTTP/1.1 1-16-0/0/24187. 0.001106029438279190650.00.00582.32 127.0.0.1http/1.1www.businessofapps.com:8080GET /news/aps-london-early-bird-tickets-end-friday/ HTTP/1.1 1-16-0/0/24526. 0.001106022399279646720.00.00540.36 127.0.0.1http/1.1www.businessofapps.com:8080GET /login?mdrv=www.businessofapps.com HTTP/1.1 1-16-0/0/24529. 0.001106024574282318000.00.00540.65 127.0.0.1http/1.1www.businessofapps.com:8080GET /data/app-data/?mdrv=www.businessofapps.com HTTP/1.1 1-16-0/0/24493. 0.001106021747285070520.00.00490.50 127.0.0.1http/1.1www.businessofapps.com:8080GET /data/app-rankings/?mdrv=www.businessofapps.com HTTP/1.1 1-16-0/0/24375. 0.001106012449290544520.00.00589.04 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/mobile-ad-analytics/?mdrv=www.businessofapps.com HTTP/ 1-16-0/0/24398. 0.001106022295283014930.00.00560.53 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/offerwalls HTTP/1.1 1-16-0/0/24297. 0.001106019963295946990.00.00515.26 127.0.0.1http/1.1www.businessofapps.com:8080GET /video-category/user-acquisition/?mdrv=www.businessofapps.c 1-16-0/0/24345. 0.001106027840286755470.00.00498.80 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/ad-fraud/ad-servers/ssp/app-installs/ssp/ad-se 1-16-0/0/24465. 0.001106020697277754360.00.00529.88 127.0.0.1http/1.1www.businessofapps.com:8080GET /news/mena-3-game-revenues-to-grow-56-by-2026/ HTTP/1.1 1-16-0/0/24568. 0.001106020488288343030.00.00588.86 127.0.0.1http/1.1www.businessofapps.com:8080GET /video-category/subscriptions/?mdrv=www.businessofapps.com 1-16-0/0/24478. 0.001106023921284226550.00.00542.12 127.0.0.1http/1.1www.businessofapps.com:8080GET /facebooks-mobile-audience-growing-mobile-ad-revenue-reflec 1-16-0/0/24495. 0.001106022864283152880.00.00614.55 127.0.0.1http/1.1www.businessofapps.com:8080GET /register?mdrv=www.businessofapps.com HTTP/1.1 1-16-0/0/24556. 0.001106020896282859210.00.00496.93 127.0.0.1http/1.1www.businessofapps.com:8080GET /data/app-market/?mdrv=www.businessofapps.com HTTP/1.1 1-16-0/0/24459. 0.001106023481275046740.00.00561.54 127.0.0.1http/1.1www.businessofapps.com:8080GET /data/app-sectors/?mdrv=www.businessofapps.com HTTP/1.1 1-16-0/0/24484. 0.001106017793277749110.00.00504.16 127.0.0.1http/1.1www.businessofapps.com:8080GET /insights/app-developers/?mdrv=www.businessofapps.com HTTP/ 1-16-0/0/24380. 0.001106018464286057300.00.00482.92 127.0.0.1http/1.1www.businessofapps.com:8080GET /podcasts/app-engagement/?mdrv=www.businessofapps.com HTTP/ 1-16-0/0/24329. 0.001106022384275989670.00.00497.35 127.0.0.1http/1.1www.businessofapps.com:8080GET /app-leaders/?mdrv=www.businessofapps.com HTTP/1.1 1-16-0/0/24323. 0.001106021833284695380.00.00548.9
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb31350f87f6350f87f68f9d722f
Apache Status Apache Server Status for 52.56.202.188 (via 127.0.0.1) Server Version: Apache/2.4.41 (Ubuntu) mod_fcgid/2.3.9 Server MPM: event Server Built: 2023-03-08T17:32:54 Current Time: Monday, 16-Oct-2023 00:59:09 BST Restart Time: Tuesday, 10-Oct-2023 18:19:51 BST Parent Server Config. Generation: 7 Parent Server MPM Generation: 6 Server uptime: 5 days 6 hours 39 minutes 17 seconds Server load: 2.06 1.44 1.41 Total accesses: 1155979 - Total Traffic: 27.1 GB - Total Duration: 1422510348 CPU Usage: u29.42 s16.42 cu3625.75 cs582.11 - .933% CPU load 2.54 requests/sec - 62.3 kB/second - 24.6 kB/request - 1230.57 ms/request 2 requests currently being processed, 48 idle workers SlotPIDStoppingConnections ThreadsAsync connections totalacceptingbusyidlewritingkeep-aliveclosing 31627108no5yes223020 51627107no1yes025000 Sum206 248020 ................................................................ ...........__W_______________W______.........................___ ______________________ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMCPU SSReqDurConnChildSlotClientProtocolVHostRequest 0-5-0/0/8295. 0.001338412046110069630.00.00196.98 127.0.0.1http/1.1www.businessofapps.com:8080GET /app-leaders/ariana-alexander-sefre/ HTTP/1.1 0-5-0/0/8262. 0.001338411094100927140.00.00195.58 127.0.0.1http/1.1www.businessofapps.com:8080GET /subscribe-app-engagement-monthly/ HTTP/1.1 0-5-0/0/8312. 0.00133849797109245130.00.00225.70 127.0.0.1http/1.1www.businessofapps.com:8080GET /insights/user-acquisition/ HTTP/1.1 0-5-0/0/8287. 0.00133848404102504390.00.00199.35 127.0.0.1http/1.1www.businessofapps.com:8080GET /video-category/user-acquisition/ HTTP/1.1 0-5-0/0/8235. 0.001338412479100106020.00.00245.42 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/apple-search-ads/ HTTP/1.1 0-5-0/0/8317. 0.001338414055100216650.00.00207.41 127.0.0.1http/1.1www.businessofapps.com:8080GET /video-category/app-growth/ HTTP/1.1 0-5-0/0/8327. 0.00133849813105181360.00.00200.88 127.0.0.1http/1.1www.businessofapps.com:8080GET /subscribe-aso-weekly/ HTTP/1.1 0-5-0/0/8284. 0.001338413614106796780.00.00242.97 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/game-monetization/ HTTP/1.1 0-5-0/0/8376. 0.001338413849107949550.00.00197.63 127.0.0.1http/1.1www.businessofapps.com:8080GET /webinars/ HTTP/1.1 0-5-0/0/8328. 0.001338411537104725880.00.00193.92 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/remerge/ HTTP/1.1 0-5-0/0/8268. 0.00133841062798882030.00.00197.62 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/app-installs/ HTTP/1.1 0-5-0/0/8257. 0.001338412796103153520.00.00188.08 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/mobile-ad-network/ HTTP/1.1 0-5-0/0/8321. 0.001338413718103792370.00.00199.77 127.0.0.1http/1.1www.businessofapps.com:8080GET /advertise/ HTTP/1.1 0-5-0/0/8258. 0.00133849449107274720.00.00221.25 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/compare/app-installs/retargeting/ssp/ad-servers/app-in 0-5-0/0/8311. 0.0013384768397411690.00.00205.01 127.0.0.1http/1.1www.businessofapps.com:8080GET /data/metrics/ HTTP/1.1 0-5-0/0/8338. 0.001338413392104358520.00.00196.21 127.0.0.1http/1.1www.businessofapps.com:8080GET /?p=76305 HTTP/1.1 0-5-0/0/8252. 0.001338414128109571070.00.00193.16 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/mobile-ad-analytics/ HTTP/1.1 0-5-0/0/8268. 0.001338413428106016220.00.00183.99 127.0.0.1http/1.1www.businessofapps.com:8080GET /register HTTP/1.1 0-5-0/0/8248. 0.00133849608106444690.00.00232.75 127.0.0.1http/1.1www.businessofapps.com:8080GET /insights/app-engagement/ HTTP/1.1 0-5-0/0/8301. 0.001338410895104936350.00.00185.28 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/zoomd/ HTTP/1.1 0-5-0/0/8245. 0.00133849814104291930.00.00188.36 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/remerge HTTP/1.1 0-5-0/0/8314. 0.001338414093105740550.00.00243.98 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/app-marketing/ HTTP/1.1 0-5-0/0/8330. 0.00133849704104036740.00.00203.38 127.0.0.1http/1.1www.businessofapps.com:8080GET /subscribe-ua-weekly/ HTTP/1.1 0-5-0/0/8173. 0.00133841343198491550.00.00202.03 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/influencer-marketing/platforms/ HTTP/1.1 0-5-0/0/8303. 0.001338411246103513540.00.00268.10 127.0.0.1http/1.1www.businessofapps.com:8080GET /%25%27%20RLIKE%20%28SELECT%20%28CASE%20WHEN%20%286548%3D97 1-5-0/0/8491. 0.00133846788109072460.00.00245.97 127.0.0.1http/1.1www.businessofapps.com:8080GET /events HTTP/1.1 1-5-0/0/8658. 0.001338413444108586410.00.00181.31 127.0.0.1http/1.1www.businessofapps.com:8080GET /events/ HTTP/1.1 1-5-0/0/8708. 0.001338412273108144750.00.00179.16 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/ad-exchanges/ HTTP/1.1 1-5-0/0/8697. 0.001338410477107331410.00.00186.99 127.0.0.1http/1.1www.businessofapps.com:8080GET /podcasts/app-store-optimization/ HTTP/1.1 1-5-0/0/8559. 0.00133847981115424470.00.00232.42 127.0.0.1http/1.1www.businessofapps.com:8080POST /wp-admin/admin-ajax.php HTTP/1.1 1-5-0/0/8570. 0.001338412266108357670.00.00243.26 127.0.0.1http/1.1www.businessofapps.com:8080GET /data/?sort_order=ASC&sort_orderby=revenue HTTP/1.1 1-5-0/0/8567. 0.001338412041110813200.00.00199.13 127.0.0.1http/1.1www.businessofapps.com:8080GET /register/ HTTP/1.1 1-5-0/0/8593. 0.001338415153109056640.00.00191.84 127.0.0.1http/1.1www.businessofapps.com:8080GET /affiliate/ HTTP/1.1 1-5-0/0/8645. 0.001338411013108536080.00.00185.46 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/app-builders/ HTTP/1.1 1-5-0/0/8669. 0.001338411883111470830.00.00189.93 127.0.0.1http/1.1www.businessofapps.com:8080GET /app-developer-platform/android/ HTTP/1.1 1-5-0/0/8658. 0.001338410431110095780.00.00219.44 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/app-store-optimization/ HTTP/1.1 1-5-0/0/8667. 0.001338413498111465250.00.00248.12 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/performance-marketing/ HTTP/1.1 1-5-0/0/8630. 0.00133848574109103270.00.00179.79 127.0.0.1http/1.1www.businessofapps.com:8080GET /ads/ HTTP/1.1 1-5-0/0/8671. 0.001338411767104272380.00.00239.41 127.0.0.1http/1.1www.businessofapps.com:8080GET /downloads/ HTTP/1.1 1-5-0/0/8684. 0.00133847150103978870.00.00182.06 127.0.0.1http/1.1www.businessofapps.com:8080GET /data/app-market/ HTTP/1.1 1-5-0/0/8572. 0.00133849110110674400.00.00187.08 127.0.0.1http/1.1www.businessofapps.com:8080GET /podcasts/user-acquisition/ HTTP/1.1 1-5-0/0/8485. 0.001338413568107011740.00.00179.72 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/marketing-automation/ HTTP/1.1 1-5-0/0/8561. 0.001338410763106506980.00.00176.24 127.0.0.1http/1.1www.businessofapps.com:8080GET /app-developers/india/ HTTP/1.1 1-5-0/0/8670. 0.001338413612103317050.00.00189.33 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/influencer-marketing/we%20manage%20digital-fir 1-5-0/0/8615. 0.00133849421110298690.00.00179.56 127.0.0.1http/1.1www.businessofapps.com:8080GET /podcasts/app-marketing/ HTTP/1.1 1-5-0/0/8647. 0.00133848334105987520.00.00183.22 127.0.0.1http/1.1www.businessofapps.com:8080GET /marketplace/app-monetization/ HTTP/1.1 1-5-0/0/8625. 0.00133848970