Popular sites with Apache server-status enabled (leaking internal details)
1–10 of 47 posts
Re: Popular sites with Apache server-status enabled (leaking internal details)
#2Re: Popular sites with Apache server-status enabled (leaking internal details)
#3Re: Popular sites with Apache server-status enabled (leaking internal details)
#4Re: Popular sites with Apache server-status enabled (leaking internal details)
#5Aren't the exposed client IPs at http://php.net/server-status/ a pretty big deal??
http://www.apache.org/server-status
Additionally, mod_info is enabled, which lets you read nearly the entire running configuration:
Re: Popular sites with Apache server-status enabled (leaking internal details)
#6Previous discussion: http://news.ycombinator.com/item?id=4661625
Re: Popular sites with Apache server-status enabled (leaking internal details)
#7Site is down for me, but I thought we agreed last time this was on HN it wasn't really that big of a deal.. Previous discussion: http://news.ycombinator.com/item?id=4661625
Re: Popular sites with Apache server-status enabled (leaking internal details)
#8Site is down for me, but I thought we agreed last time this was on HN it wasn't really that big of a deal.. Previous discussion: http://news.ycombinator.com/item?id=4661625
Re: Popular sites with Apache server-status enabled (leaking internal details)
#9Re: Popular sites with Apache server-status enabled (leaking internal details)
#10Site is down for me, but I thought we agreed last time this was on HN it wasn't really that big of a deal.. Previous discussion: http://news.ycombinator.com/item?id=4661625
Yeah, not sure I'd agree with it not being a big deal. Especially with the type of recon you can do on this information as an attacker.
TP