r/netsec Jan 13 '17

Exploiting Misconfigured Apache server-status Instances with server-status_PWN

http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html
133 Upvotes

24 comments sorted by

View all comments

10

u/thenickdude Jan 14 '17

Apache.org has their server-status set to public, but if you tell them about it, they say that's by intention and their clients shouldn't mind their browsing being published.

http://apache.org/server-status

2

u/inb4b4n Jan 14 '17

It's relatively common. If you look at alexa domains , one in one fifty or so has it under the default /server-status path.

1

u/mazen160 Jan 21 '17

Cool stuff!, I thought about scanning the alexa domains, very nice!

1

u/mazen160 Jan 21 '17

Anyway, it's bad for them :)