All fixes

Lock down the server-status page

exposed-server-status

The Apache server-status page shows live requests, client addresses and internal IPs to anyone who asks. Restrict it to localhost or remove it.

Why this matters

Your server's status page is publicly accessible. It shows traffic and internal IPs — useful reconnaissance for attackers but not directly exploitable.

Nginx

  1. 1 Restrict stub_status to localhost
nginx
location /nginx_status {
    stub_status;
    allow 127.0.0.1;
    deny all;
}

Does your app still have this?

Scan your domain