This has happened the second time in this week.

Leaving default setting open after the product has been released can cause serious problems for the product users.

Latest to join this default party is Tor.

Default settings on Apache Web servers can reveal details about Tor traffic

As you know, the dark web which hosts .onion websites can be accessed using Tor anonymity web client.

This was reported to the Tor Project admin and also covered on Reddit but to no avail.

The Apache server setting causing this issue is the Server Status module which comes activated by default.

Sample server activity log from a real-life Tor website hosted on an Apache server

spot_img

source: www.techworm.net