Lock down the server-status page
exposed-server-status
The Apache server-status page shows live requests, client addresses and internal IPs to anyone who asks. Restrict it to localhost or remove it.
Why this matters
Your server's status page is publicly accessible. It shows traffic and internal IPs — useful reconnaissance for attackers but not directly exploitable.
Web servers
Nginx
- 1 Restrict stub_status to localhost
nginx
location /nginx_status {
stub_status;
allow 127.0.0.1;
deny all;
}Does your app still have this?
Scan your domain