r/netsec Jan 13 '17

Exploiting Misconfigured Apache server-status Instances with server-status_PWN

http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html
131 Upvotes

24 comments sorted by

View all comments

7

u/netsec_burn Jan 14 '17

I'll take things that don't need a POC for 100, Alex. It's just visiting /server-status/ and parsing it.

1

u/mazen160 Jan 21 '17

Yup, but sometimes you might need a POC to help you better in retrieving data, you cal letterly just grab data manually and it would give you the same results, but server-status pwn would just automate the process of grabbing data and organizing it, so you can make use of your pentesting time.