| Tor onion services are designed to conceal the network location of their hosting infrastructure, which makes attribution difficult. However, Apache server-status pages can unintentionally expose infrastructure information when onion-service traffic is forwarded to a local web server. In this configuration, Apache may treat requests arriving through Tor as localhost traffic and allow access to a page intended to be restricted to the local machine. We analyze 210,121 validated server-status snapshots from 12,591 onion services collected between November 2019 and March 2025. We show how fields such as via, VHost, and the Workers Table can reveal public IP addresses, provider-specific hostnames, and other infrastructure leads. Repeated observations show that this exposure persisted throughout the measurement period, with hundreds to thousands of affected onion services active at a time. We also present a real-world case in which an exposed VPS hostname provided a key technical lead to the hosting infrastructure of two large child sexual abuse material platforms. Follow-up by German law enforcement contributed to the identification of the alleged operator and the takedown of both services. These findings show that exposed server-status pages provide a passive source of infrastructure attribution leads without attacking the Tor protocol itself. |