The server-status page (usually /server-status
) allows server administrators to find out how well their server is performing.
This is a HTML page that gives the current server statistics such as the server version, up time,cpu, ram, and information about requests made to the server.
This information can be very useful if the application is sent sensitive information as GET requests. If you monitor this page you might be able to find CSRF tokens, API keys, hidden paths, and other sensitive information being sent to the server.
https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb318acb2ce88acb2ce8b8047f50
Apache Status Apache Server Status for 81.173.66.188 (via 192.168.226.13) Server Version: Apache/2.4.10 (Win32) OpenSSL/1.0.1h PHP/5.4.31 Server MPM: WinNT Apache Lounge VC9 Server Built: Jul 19 2014 13:07:40 Current Time: Tuesday, 04-Oct-2022 18:37:53 West-Europa (zomertijd) Restart Time: Thursday, 29-Sep-2022 13:51:49 West-Europa (zomertijd) Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 5 days 4 hours 46 minutes 4 seconds Server load: -1.00 -1.00 -1.00 Total accesses: 73 - Total Traffic: 26 kB .000163 requests/sec - 0 B/second - 364 B/request 11 requests currently being processed, 139 idle workers ________________________________________________________________ ________________________________________________________________ ________CWCWW_WWW_CWW_ Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMSSReqConnChildSlotClientVHostRequest 0-011281/2/2C 04060.00.000.00 46.101.135.117localhost:80GET /.git/config HTTP/1.1 0-011281/2/2C 03900.00.000.00 46.101.135.117localhost:80GET /?rest_route=/wp/v2/users/ HTTP/1.1 0-011281/2/2C 02340.00.000.00 46.101.135.117localhost:80GET / HTTP/1.1 0-011281/26/26C 05310.00.010.01 46.101.135.117localhost:80GET /debug/default/view?panel=config HTTP/1.1 0-011280/1/1W 000.00.000.00 46.101.135.117localhost:80GET /telescope/requests HTTP/1.1 0-011280/1/1_ 141573620.00.000.00 178.79.186.216localhost:80GET /?rest_route=/wp/v2/users/ HTTP/1.1 0-011281/2/2C 05780.00.000.00 46.101.135.117localhost:80GET /.env HTTP/1.1 0-011280/2/2W 000.00.000.00 46.101.135.117localhost:80GET /server-status HTTP/1.1 0-011281/2/2C 05460.00.000.00 46.101.135.117localhost:80GET /info.php HTTP/1.1 0-011280/2/2_ 1415733120.00.000.00 178.79.186.216localhost:80GET /debug/default/view?panel=config HTTP/1.1 0-011281/3/3C 02960.00.000.00 46.101.135.117localhost:80GET /s/38312e3137332e36362e313838/_/;/META-INF/maven/com.atlass 0-011281/5/5C 06090.00.000.00 46.101.135.117localhost:80GET /.DS_Store HTTP/1.1 0-011281/25/25C 06400.00.010.01 46.101.135.117localhost:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-011280/4/4_ 1415728280.00.010.01 178.79.186.216localhost:80GET /server-status HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss Apache/2.4.10 (Win32) OpenSSL/1.0.1h PHP/5.4.31 Server at 81.173.66.188 Port 89
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb318acb2ce88acb2ce845c477be
Apache Status Apache Server Status for 81.173.66.188 (via 192.168.226.13) Server Version: Apache/2.4.10 (Win32) OpenSSL/1.0.1h PHP/5.4.31 Server MPM: WinNT Apache Lounge VC9 Server Built: Jul 19 2014 13:07:40 Current Time: Monday, 03-Oct-2022 03:18:19 West-Europa (zomertijd) Restart Time: Thursday, 29-Sep-2022 13:51:49 West-Europa (zomertijd) Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 3 days 13 hours 26 minutes 30 seconds Server load: -1.00 -1.00 -1.00 Total accesses: 33 - Total Traffic: 9 kB .000107 requests/sec - 0 B/second - 279 B/request 10 requests currently being processed, 140 idle workers ________________________________________________________________ ________________________________________________________________ ____________WCWCWWWWWW Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMSSReqConnChildSlotClientVHostRequest 0-011281/1/1C 03120.00.000.00 178.79.186.216localhost:80GET /telescope/requests HTTP/1.1 0-011281/1/1C 0620.00.000.00 178.79.186.216localhost:80GET /?rest_route=/wp/v2/users/ HTTP/1.1 0-011281/1/1C 02960.00.000.00 178.79.186.216localhost:80GET /info.php HTTP/1.1 0-011281/1/1C 0150.00.000.00 178.79.186.216localhost:80GET / HTTP/1.1 0-011281/1/1C 03120.00.000.00 178.79.186.216localhost:80GET /.git/config HTTP/1.1 0-011281/2/2C 03120.00.000.00 178.79.186.216localhost:80GET /debug/default/view?panel=config HTTP/1.1 0-011281/2/2C 03120.00.000.00 178.79.186.216localhost:80GET /.env HTTP/1.1 0-011281/4/4C 03120.00.000.00 178.79.186.216localhost:80GET /s/38312e3137332e36362e313838/_/;/META-INF/maven/com.atlass 0-011281/24/24C 03120.00.010.01 178.79.186.216localhost:80GET /.DS_Store HTTP/1.1 0-011280/3/3W 000.00.000.00 178.79.186.216localhost:80GET /server-status HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss Apache/2.4.10 (Win32) OpenSSL/1.0.1h PHP/5.4.31 Server at 81.173.66.188 Port 89
Severity: medium
Fingerprint: ee80c6706842d3ef6842d3ef6325bb316325bb318acb2ce88acb2ce83ca64246
Apache Status Apache Server Status for 81.173.66.188 (via 192.168.226.13) Server Version: Apache/2.4.10 (Win32) OpenSSL/1.0.1h PHP/5.4.31 Server MPM: WinNT Apache Lounge VC9 Server Built: Jul 19 2014 13:07:40 Current Time: Friday, 10-Jun-2022 12:11:07 West-Europa (zomertijd) Restart Time: Thursday, 09-Jun-2022 13:06:36 West-Europa (zomertijd) Parent Server Config. Generation: 1 Parent Server MPM Generation: 0 Server uptime: 23 hours 4 minutes 30 seconds Server load: -1.00 -1.00 -1.00 Total accesses: 5 - Total Traffic: 0 kB 6.02e-5 requests/sec - 0 B/second - 0 B/request 8 requests currently being processed, 142 idle workers ________________________________________________________________ ________________________________________________________________ ______________WWWWWWWW Scoreboard Key: "_" Waiting for Connection, "S" Starting up, "R" Reading Request, "W" Sending Reply, "K" Keepalive (read), "D" DNS Lookup, "C" Closing connection, "L" Logging, "G" Gracefully finishing, "I" Idle cleanup of worker, "." Open slot with no current process SrvPIDAccMSSReqConnChildSlotClientVHostRequest 0-019561/1/1C 0620.00.000.00 146.190.226.130localhost:80GET /login.action HTTP/1.1 0-019561/1/1C 0780.00.000.00 146.190.226.130localhost:80GET /config.json HTTP/1.1 0-019561/1/1C 02030.00.000.00 146.190.226.130localhost:80GET /telescope/requests HTTP/1.1 0-019560/0/0W 000.00.000.00 146.190.226.130localhost:80GET /server-status HTTP/1.1 0-019561/1/1C 02030.00.000.00 146.190.226.130localhost:80GET /.env HTTP/1.1 0-019561/2/2C 02180.00.000.00 146.190.226.130localhost:80GET /s/38312e3137332e36362e313838/_/;/META-INF/maven/com.atlass 0-019560/1/1_ 03120.00.000.00 146.190.226.130localhost:80GET /.DS_Store HTTP/1.1 0-019561/1/1C 03120.00.000.00 146.190.226.130localhost:80GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.expor 0-019561/1/1C 03280.00.000.00 146.190.226.130localhost:80GET /.git/config HTTP/1.1 0-019561/5/5C 02500.00.000.00 146.190.226.130localhost:80GET /info.php HTTP/1.1 SrvChild Server number - generation PIDOS process ID AccNumber of accesses this connection / this child / this slot MMode of operation SSSeconds since beginning of most recent request ReqMilliseconds required to process most recent request ConnKilobytes transferred this connection ChildMegabytes transferred this child SlotTotal megabytes transferred this slot SSL/TLS Session Cache Status: cache type: SHMCB, shared memory: 512000 bytes, current entries: 0subcaches: 32, indexes per subcache: 88index usage: 0%, cache usage: 0%total entries stored since starting: 0total entries replaced since starting: 0total entries expired since starting: 0total (pre-expiry) entries scrolled out of the cache: 0total retrieves since starting: 0 hit, 0 misstotal removes since starting: 0 hit, 0 miss Apache/2.4.10 (Win32) OpenSSL/1.0.1h PHP/5.4.31 Server at 81.173.66.188 Port 89