Live data from Hacker News

Popular sites with Apache server-status enabled (leaking internal details)

blog.sucuri.net

31–40 of 47 posts

Re: Popular sites with Apache server-status enabled (leaking internal details)

#32

Aren't the exposed client IPs at http://php.net/server-status/ a pretty big deal??

Why is that a big deal? Is exposing the public IPs of some random people really an issue?

If there is no reason for it to be public, then it shouldn't be public, no matter how obscure the issues with it may seem to you.

Re: Popular sites with Apache server-status enabled (leaking internal details)

#33
post #12

To those who think it isn't a big deal: when GET requests are made public you can snoop "password reset links" and similar to to get access to somebody else's account. Even when developers use best practices GET request paths can leak sensitive information.

Some of the sites at http://urlfind.org/?server-status even keep a session id in the URL -- look for PHPSESSID.

Re: Popular sites with Apache server-status enabled (leaking internal details)

#34
post #30

Earlier quoted context omitted.

Why is that a big deal? Is exposing the public IPs of some random people really an issue?

http://furry-incest-porn.xxx/server-status/ Yes, it's potentially an issue.

Sure, for a skeezy site. The parent was talking specifically about php.org, I can't imagine any real risk for a site like that exposing their visitor ip log.

Re: Popular sites with Apache server-status enabled (leaking internal details)

#35
post #31

Looks like Disney fixed theirs. Can't believe there are admins at this level that miss this.

Why do you think Disney has access to high quality admins? Do you know high quality sysadmins who want to work for Disney, or companies like it?

Just because a company is a big name doesn't mean it attracts big talent. Disney is still fishing from the same ocean where all the best engineers went to sexier places.

Re: Popular sites with Apache server-status enabled (leaking internal details)

#36

Aren't the exposed client IPs at http://php.net/server-status/ a pretty big deal??

Why is that a big deal? Is exposing the public IPs of some random people really an issue?

It's not just that. You can get an idea of the traffic to the site if you watch for a while. When that information might be commercially sensitive then it could be a genuine issue.

For example, nba.com has been averaging about 3 connections and 1021 idle workers while I've been watching it. That's perhaps less traffic than you might expect? I don't know, but if I were paying for ad space I might be interested.

Re: Popular sites with Apache server-status enabled (leaking internal details)

#37
post #31

Looks like Disney fixed theirs. Can't believe there are admins at this level that miss this.

Why do you think Disney has access to high quality admins? Do you know high quality sysadmins who want to work for Disney, or companies like it? Just because a company is a big name doesn't mean it attracts big talent. Disney is still fishing from the same ocean where all the best engineers went to sexier places.

My comment was really 2 separate statements, I don't necessarily think Disney has a 'rock star' admin(s). But you make a valid point.

Also, I think I don't get paid enough.

Re: Popular sites with Apache server-status enabled (leaking internal details)

#38
post #36

Earlier quoted context omitted.

Why is that a big deal? Is exposing the public IPs of some random people really an issue?

It's not just that. You can get an idea of the traffic to the site if you watch for a while. When that information might be commercially sensitive then it could be a genuine issue. For example, nba.com has been averaging about 3 connections and 1021 idle workers while I've been watching it. That's perhaps less traffic than you might expect? I don't know, but if I were paying for ad space I might be interested.

Seems like a great way to test your DDOS toolset with real-world targets.

Re: Popular sites with Apache server-status enabled (leaking internal details)

#40
Even a cursory scan of the http://urlfind.org/?server-status list reveals scads of porn sites exposing their visitor's IP addresses:

(Note these links go to Apache server-status pages at the time of linking. This may change if the server admins wise up - to be on the safe side consider them NSFW):

  http://black-tgirls.com/server-status
  http://badexgfs.com/server-status
  http://tubepornx.com/server-status
  http://lesbianvalley.net/server-status
  ..... and many more .....
Personally, I don't care what consenting adults do with their genitals. But I think it's safe to assume that the visitors to these sites expect a certain level of privacy that's not being met.
Post reply on HN