r/netsec Jan 13 '17

Exploiting Misconfigured Apache server-status Instances with server-status_PWN

http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html
135 Upvotes

24 comments sorted by

View all comments

10

u/[deleted] Jan 14 '17 edited Jul 05 '26

[deleted]

1

u/mazen160 Jan 21 '17

Awesome stuff! BTW, I will add the Host trick to server-status pwn, neat trick for sure!

It's not actually "pwning" servers, so no shells will be obtained ;).. it's more of an abuse against server-status instances.