[tor-bugs] #30419 [Internal Services/Tor Sysadmin Team]: Apache's server-status page accessible via TPO onion services

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon May 6 22:56:49 UTC 2019


#30419: Apache's server-status page accessible via TPO onion services
-------------------------+-------------------------------------------------
 Reporter:  Parckwart    |          Owner:  tpa
     Type:  defect       |         Status:  new
 Priority:  Medium       |      Component:  Internal Services/Tor Sysadmin
                         |  Team
  Version:               |       Severity:  Normal
 Keywords:               |  Actual Points:
Parent ID:               |         Points:
 Reviewer:               |        Sponsor:
-------------------------+-------------------------------------------------
 The following Apache ''server-status'' pages are accessible, leaking IP
 addresses of TPO website visitors:

 2d5quh2deowe4kpd.onion/server-status
 2iqyjmvrkrq5h5mg.onion/server-status
 4bflp2c4tnynnbes.onion/server-status
 52g5y5karruvc7bz.onion/server-status
 54nujbl4qohb5qdp.onion/server-status
 bn6kma5cpxill4pe.onion/server-status
 bo7uextohjpuqvrh.onion/server-status
 bogdyardcfurxcle.onion/server-status
 buqlpzbbcyat2jiy.onion/server-status
 c5qrls2slxqz6vdw.onion/server-status
 dgvdmophvhunawds.onion/server-status
 ea5faa5po25cf7fb.onion/server-status
 ebxqgaz3dwywcoxl.onion/server-status
 expyuzz4wqqyqhjn.onion/server-status
 fhny6b7b6sbslc2b.onion/server-status
 fqnqc7zix2wblwex.onion/server-status
 fr6scuhdp5dqvy7d.onion/server-status
 fylvgu5r6gcdadeo.onion/server-status
 hzmun3rnnxjhkyhg.onion/server-status
 icxe4yp32mq6gm6n.onion/server-status
 jqs44zhtxl2uo6gk.onion/server-status
 klbl4glo2btuwyok.onion/server-status
 krkzagd5yo4bvypt.onion/server-status
 kzcx36ytbsm5iogs.onion/server-status
 l3xrunzkfufzvw2c.onion/server-status
 lfdhmyq24uacliu5.onion/server-status
 llhb3u5h3q66ha62.onion/server-status
 n46o4uxsej2icp5l.onion/server-status
 ngp5wfw5z6ms3ynx.onion/server-status
 nraswjtnyrvywxk7.onion/server-status
 nwoyhtkk4tloji3j.onion/server-status
 qigcb4g4xxbh5ho6.onion/server-status
 qrmfuxwgyzk5jdjz.onion/server-status
 rqef5a5mebgq46y5.onion/server-status
 s2bweojt5vg52e5i.onion/server-status
 sbe5fi5cka5l3fqe.onion/server-status
 sdscoq7snqtznauu.onion/server-status
 tgnv2pssfumdedyw.onion/server-status
 tngjm3owsslo3wgo.onion/server-status
 vhbbidwvzwhahsrg.onion/server-status
 vijs2fmpd72nbqok.onion/server-status
 vt5hknv6sblkgf22.onion/server-status
 wcgqzqyfi7a6iu62.onion/server-status
 x3nelbld33llasqv.onion/server-status
 y7pm6of53hzeb7u2.onion/server-status
 yabd3wlpvybdnvzg.onion/server-status
 yjuwkcxlgo7f7o6s.onion/server-status
 yz7lpwfhhzcdyc5y.onion/server-status

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/30419>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list