Skip to content

Comment on Popular sites with Apache server-status enabled (leaking internal details)

Comments

Site is down for me, but I thought we agreed last time this was on HN it wasn't really that big of a deal..

Previous discussion: http://news.ycombinator.com/item?id=4661625

Thanks for the update withe link.

Yeah, not sure I'd agree with it not being a big deal. Especially with the type of recon you can do on this information as an attacker.

TP

I believe the consensus was that it was not a big deal for www.php.net to have the server status page up. The original link for that news item was http://php.net/server-status. However, not all sites are like php.net which is used mainly for documentation (it would appear). That said, a status page leaking IPs or sessions (PHPSESSIONID) for a private forum, government agency, etc, could be a different story.

Edited: Typo

Gotta ask, is there any benefit to having the server status open to public?

When was it last on HN? Don't remember seeing it.

It's back up now.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.