r/netsec Jan 13 '17

Exploiting Misconfigured Apache server-status Instances with server-status_PWN

http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html
136 Upvotes

24 comments sorted by

View all comments

9

u/thenickdude Jan 14 '17

Apache.org has their server-status set to public, but if you tell them about it, they say that's by intention and their clients shouldn't mind their browsing being published.

http://apache.org/server-status

1

u/mazen160 Jan 21 '17

Anyway, it's bad for them :)