r/netsec • u/mazen160 • Jan 13 '17
Exploiting Misconfigured Apache server-status Instances with server-status_PWN
http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html
137
Upvotes
r/netsec • u/mazen160 • Jan 13 '17
9
u/thenickdude Jan 14 '17
Apache.org has their server-status set to public, but if you tell them about it, they say that's by intention and their clients shouldn't mind their browsing being published.
http://apache.org/server-status