Search
Search titles only
By:
Search titles only
By:
Menu
Forums
New posts
Search forums
Home
What's new
New posts
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Reply to thread
Home
Computers & Internet
Domain Names & Hosting
November 2021 Web Server Survey
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
[QUOTE="Netcraft, post: 560"] In the [B]November 2021[/B] survey we received responses from [B]1,175,392,792[/B] sites across [B]267,027,794[/B] unique domains and [B]11,525,855[/B] web-facing computers. This reflects a loss of 4.06 million sites, but a gain of 1.60 million domains and 137,000 computers. nginx gained the largest number of domains (+741,000) and web-facing computers (+81,300) this month and continues to lead in both metrics with market shares of 30.1% and 37.3%. Further down in the market, there was also a noticeable increase in the total number of web-facing computers running LiteSpeed, which went up by 11,200 to 101,000 (+12.5%), although this resulted in only a 1.44% increase in domains. These counts include sites that run on LiteSpeed Web Server and its open source variant, OpenLiteSpeed, both of which exhibit the same “LiteSpeed” server banner. Both nginx and Apache lost nearly 4 million hostnames each, reducing their sites market shares to 34.7% and 24.4%. Meanwhile, Cloudflare gained 1.15 million sites, which has taken its total up to 58.6 million (+2.00%) and increased its sites share to 4.99%. nginx and Apache also suffered losses amongst the top million websites, paving the way for Microsoft to increase its presence by 2,369 sites (+3.75%). Microsoft web server software is now used by 65,600 of the top million sites, but Apache is still the most commonly used web server in this sector, with 240,000 of the top million sites using it, and nginx is not far behind with 224,000. [HEADING=2]Apache 2.4.49 vulnerability[/HEADING] Following last month’s news of a path traversal vulnerability in Apache 2.4.49 being [URL='https://news.netcraft.com/archives/2021/10/15/october-2021-web-server-survey.html']actively exploited in the wild[/URL], this month’s survey shows that more than 11 million websites had server banners containing “Apache/2.4.49” before a fix was released. The only other version vulnerable to attack was Apache 2.4.50, which failed to fix the vulnerability properly – but this version was released after the survey ran and was promptly replaced with Apache 2.4.51, where the vulnerability was resolved properly. The true number of websites that were vulnerable during the survey period is likely to have been much greater than the 11 million websites that openly reported themselves to be running Apache 2.4.49, as nearly two-thirds of all Apache-powered websites do not reveal a version number in their server banners. This configuration is often a deliberate act towards security through obscurity, although attackers can often deduce precise version numbers by carrying out additional tests. There may also have been additional vulnerable instances of Apache 2.4.49 hidden behind frontend load balancers or content delivery networks such as Cloudflare. Conversely, some websites running on Apache 2.4.49 may not have been vulnerable if they used an appropriately configured web application firewall that prevents path traversal attacks. More generally, the true number of web servers that contain a version-specific vulnerability can also be masked by future backported security patches, which typically fix vulnerabilities without changing the apparent version number of the software. From an external perspective, a server might appear to be running a vulnerable software version but may not actually be vulnerable to the issues affecting that version. [HEADING=2]Vendor news[/HEADING] [LIST] [*]LiteSpeed Web Server [URL='https://www.litespeedtech.com/products/litespeed-web-server/release-log']6.0.11[/URL] was released on 10 November. This is the latest version in the LSWS 6.0 stream and includes improvements in HTTP/2 and HTTP/3 throughput, new support for WebSocket proxy targets in rewrite rules, and several bugfixes. [*]Microsoft has announced new [URL='https://www.microsoft.com/en-us/msrc/bounty-microsoft-azure?SilentAuth=1&rtc=1']Azure Bounty Program[/URL] rewards of up to [URL='https://msrc-blog.microsoft.com/2021/10/18/new-high-impact-scenarios-and-awards-for-the-azure-bounty-program/']$60,000[/URL] to encourage and reward research into vulnerabilities that would have the highest potential impact on the security of its customers. [*]nginx [URL='http://nginx.org/en/CHANGES']1.21.4 mainline[/URL] was released on 2 November. This version includes some new features and changes relating to TLS and HTTP/2. [*]Lighttpd [URL='https://www.lighttpd.net/2021/10/28/1.4.61/']1.4.61[/URL] was released on 28 October to address a number of bugs. Lighttpd is used by 245,000 unique domains in this month’s survey. [*]njs [URL='http://nginx.org/en/docs/njs/index.html']0.7.0[/URL] was released on 19 October to add HTTPS support for its Fetch API, along with a few other new features and bugfixes. [*]Apache Tomcat [URL='http://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.54_%28remm%29']9.0.54[/URL], [URL='http://tomcat.apache.org/tomcat-10.0-doc/changelog.html#Tomcat_10.0.12_%28markt%29']10.0.12[/URL] and [URL='http://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.0-M6_%28markt%29']10.1.0-M6 (alpha)[/URL] were released on 1 October, followed by Tomcat [URL='http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.72_%28cschultz%29']8.5.72[/URL] on 6 October. [*][URL='https://pages.cloudflare.com/']Cloudflare Pages[/URL] now supports [URL='https://blog.cloudflare.com/custom-headers-for-pages/']custom headers[/URL] natively, without having to use Cloudflare Workers. This makes it easier for developers to add best-practice security headers and others to their JAMstack applications. [*][URL='https://blog.cloudflare.com/cloudflare-for-saas-for-all-now-generally-available/']Cloudflare for SaaS[/URL] is now generally available to all, following a [URL='https://blog.cloudflare.com/cloudflare-for-saas/']beta launch[/URL] earlier in the year. [/LIST] [IMG alt="Total number of websites"]https://news.netcraft.com/images/2021/11/wss-total.png[/IMG] [IMG alt="Web server market share"]https://news.netcraft.com/images/2021/11/wss-share.png[/IMG] [TABLE] [TR] [TH]Developer[/TH] [TH]October 2021[/TH] [TH]Percent[/TH] [TH]November 2021[/TH] [TH]Percent[/TH] [TH]Change[/TH] [/TR] [TR] [TD]nginx[/TD] [TD]412,222,221[/TD] [TD]34.95%[/TD] [TD]408,226,319[/TD] [TD]34.73%[/TD] [TD]-0.22[/TD] [/TR] [TR] [TD]Apache[/TD] [TD]290,462,410[/TD] [TD]24.63%[/TD] [TD]286,494,600[/TD] [TD]24.37%[/TD] [TD]-0.25[/TD] [/TR] [TR] [TD]OpenResty[/TD] [TD]76,038,576[/TD] [TD]6.45%[/TD] [TD]76,480,927[/TD] [TD]6.51%[/TD] [TD]0.06[/TD] [/TR] [TR] [TD]Cloudflare[/TD] [TD]57,482,103[/TD] [TD]4.87%[/TD] [TD]58,629,365[/TD] [TD]4.99%[/TD] [TD]0.11[/TD] [/TR] [/TABLE] [IMG alt="Web server market share for active sites"]https://news.netcraft.com/images/2021/11/wss-active-share.png[/IMG] [TABLE] [TR] [TH]Developer[/TH] [TH]October 2021[/TH] [TH]Percent[/TH] [TH]November 2021[/TH] [TH]Percent[/TH] [TH]Change[/TH] [/TR] [TR] [TD]Apache[/TD] [TD]48,011,801[/TD] [TD]23.92%[/TD] [TD]47,499,411[/TD] [TD]23.73%[/TD] [TD]-0.19[/TD] [/TR] [TR] [TD]nginx[/TD] [TD]41,062,259[/TD] [TD]20.45%[/TD] [TD]41,163,240[/TD] [TD]20.56%[/TD] [TD]0.11[/TD] [/TR] [TR] [TD]Google[/TD] [TD]19,233,447[/TD] [TD]9.58%[/TD] [TD]18,957,833[/TD] [TD]9.47%[/TD] [TD]-0.11[/TD] [/TR] [TR] [TD]Cloudflare[/TD] [TD]18,578,689[/TD] [TD]9.25%[/TD] [TD]18,873,075[/TD] [TD]9.43%[/TD] [TD]0.17[/TD] [/TR] [/TABLE] For more information see [URL='https://news.netcraft.com/active-sites.html']Active Sites[/URL] [IMG alt="Web server market share for top million busiest sites"]https://news.netcraft.com/images/2021/11/wss-top-1m-share.png[/IMG] [TABLE] [TR] [TH]Developer[/TH] [TH]October 2021[/TH] [TH]Percent[/TH] [TH]November 2021[/TH] [TH]Percent[/TH] [TH]Change[/TH] [/TR] [TR] [TD]Apache[/TD] [TD]240,436[/TD] [TD]24.04%[/TD] [TD]239,880[/TD] [TD]23.99%[/TD] [TD]-0.06[/TD] [/TR] [TR] [TD]nginx[/TD] [TD]224,963[/TD] [TD]22.50%[/TD] [TD]223,634[/TD] [TD]22.36%[/TD] [TD]-0.13[/TD] [/TR] [TR] [TD]Cloudflare[/TD] [TD]182,420[/TD] [TD]18.24%[/TD] [TD]183,514[/TD] [TD]18.35%[/TD] [TD]0.11[/TD] [/TR] [TR] [TD]Microsoft[/TD] [TD]63,211[/TD] [TD]6.32%[/TD] [TD]65,579[/TD] [TD]6.56%[/TD] [TD]0.24[/TD] [/TR] [/TABLE] [IMG alt="Web server market share for computers"]https://news.netcraft.com/images/2021/11/wss-computer-share.png[/IMG] [TABLE] [TR] [TH]Developer[/TH] [TH]October 2021[/TH] [TH]Percent[/TH] [TH]November 2021[/TH] [TH]Percent[/TH] [TH]Change[/TH] [/TR] [TR] [TD]nginx[/TD] [TD]4,212,329[/TD] [TD]36.99%[/TD] [TD]4,293,594[/TD] [TD]37.25%[/TD] [TD]0.27[/TD] [/TR] [TR] [TD]Apache[/TD] [TD]3,506,243[/TD] [TD]30.79%[/TD] [TD]3,519,668[/TD] [TD]30.54%[/TD] [TD]-0.25[/TD] [/TR] [TR] [TD]Microsoft[/TD] [TD]1,343,523[/TD] [TD]11.80%[/TD] [TD]1,344,322[/TD] [TD]11.66%[/TD] [TD]-0.13[/TD] [/TR] [/TABLE] [IMG alt="Web server market share for domains"]https://news.netcraft.com/images/2021/11/wss-domains-share.png[/IMG] [TABLE] [TR] [TH]Developer[/TH] [TH]October 2021[/TH] [TH]Percent[/TH] [TH]November 2021[/TH] [TH]Percent[/TH] [TH]Change[/TH] [/TR] [TR] [TD]nginx[/TD] [TD]79,496,765[/TD] [TD]29.95%[/TD] [TD]80,237,541[/TD] [TD]30.05%[/TD] [TD]0.10[/TD] [/TR] [TR] [TD]Apache[/TD] [TD]65,574,868[/TD] [TD]24.71%[/TD] [TD]65,185,640[/TD] [TD]24.41%[/TD] [TD]-0.29[/TD] [/TR] [TR] [TD]OpenResty[/TD] [TD]38,470,511[/TD] [TD]14.49%[/TD] [TD]38,800,716[/TD] [TD]14.53%[/TD] [TD]0.04[/TD] [/TR] [TR] [TD]Cloudflare[/TD] [TD]21,621,086[/TD] [TD]8.15%[/TD] [TD]22,024,974[/TD] [TD]8.25%[/TD] [TD]0.10[/TD] [/TR] [/TABLE] [/QUOTE]
Insert quotes…
Verification
Post reply
Home
Computers & Internet
Domain Names & Hosting
November 2021 Web Server Survey
Top
Bottom
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.
Accept
Learn more…