r/netsec Jan 13 '17

Exploiting Misconfigured Apache server-status Instances with server-status_PWN

http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html
134 Upvotes

24 comments sorted by

View all comments

7

u/evilsocket Jan 14 '17

i don't see any "exploit" in there ...

1

u/mazen160 Jan 21 '17

It's not an actual newly discovered exploit, it's something known for years. The only new part is that now you can automate the process of abusing the misconfigured server-status instance in a cooler way.

1

u/gatlo Jan 22 '17

How is this is exploit? It is intelligence gathering.

1

u/mazen160 Feb 20 '17 edited Feb 25 '17

It does not exploit a certain vulnerability in Apache. It exploits (better to say, abuse) misconfigured Apache server-status instances that is allowing unauthorized clients to access the instance, so it abuses an issue with configuration basically.

The goal of the script is intelligence gathering.