Can't believe there are admins at this level that miss this.
Popular sites with Apache server-status enabled (leaking internal details)
31–40 of 47 posts
Re: Popular sites with Apache server-status enabled (leaking internal details)
#32Aren't the exposed client IPs at http://php.net/server-status/ a pretty big deal??
Why is that a big deal? Is exposing the public IPs of some random people really an issue?
Re: Popular sites with Apache server-status enabled (leaking internal details)
#33To those who think it isn't a big deal: when GET requests are made public you can snoop "password reset links" and similar to to get access to somebody else's account. Even when developers use best practices GET request paths can leak sensitive information.
Re: Popular sites with Apache server-status enabled (leaking internal details)
#34Earlier quoted context omitted.
Why is that a big deal? Is exposing the public IPs of some random people really an issue?
http://furry-incest-porn.xxx/server-status/ Yes, it's potentially an issue.
Re: Popular sites with Apache server-status enabled (leaking internal details)
#35Looks like Disney fixed theirs. Can't believe there are admins at this level that miss this.
Just because a company is a big name doesn't mean it attracts big talent. Disney is still fishing from the same ocean where all the best engineers went to sexier places.
Re: Popular sites with Apache server-status enabled (leaking internal details)
#36Aren't the exposed client IPs at http://php.net/server-status/ a pretty big deal??
Why is that a big deal? Is exposing the public IPs of some random people really an issue?
For example, nba.com has been averaging about 3 connections and 1021 idle workers while I've been watching it. That's perhaps less traffic than you might expect? I don't know, but if I were paying for ad space I might be interested.
Re: Popular sites with Apache server-status enabled (leaking internal details)
#37Looks like Disney fixed theirs. Can't believe there are admins at this level that miss this.
Why do you think Disney has access to high quality admins? Do you know high quality sysadmins who want to work for Disney, or companies like it? Just because a company is a big name doesn't mean it attracts big talent. Disney is still fishing from the same ocean where all the best engineers went to sexier places.
Also, I think I don't get paid enough.
Re: Popular sites with Apache server-status enabled (leaking internal details)
#38Earlier quoted context omitted.
Why is that a big deal? Is exposing the public IPs of some random people really an issue?
It's not just that. You can get an idea of the traffic to the site if you watch for a while. When that information might be commercially sensitive then it could be a genuine issue. For example, nba.com has been averaging about 3 connections and 1021 idle workers while I've been watching it. That's perhaps less traffic than you might expect? I don't know, but if I were paying for ad space I might be interested.
Re: Popular sites with Apache server-status enabled (leaking internal details)
#39Looks like Disney fixed theirs. Can't believe there are admins at this level that miss this.
Re: Popular sites with Apache server-status enabled (leaking internal details)
#40(Note these links go to Apache server-status pages at the time of linking. This may change if the server admins wise up - to be on the safe side consider them NSFW):
http://black-tgirls.com/server-status
http://badexgfs.com/server-status
http://tubepornx.com/server-status
http://lesbianvalley.net/server-status
..... and many more .....
Personally, I don't care what consenting adults do with their genitals. But I think it's safe to assume that the visitors to these sites expect a certain level of privacy that's not being met.