I only mentioned it in the assumption they had a VM or shared hosting, in which case it's worth thinking about.
My "audience" is motivated by it being very outdated software. If non of the exploits work they will think I've patched everything.
There must be more interesting targets out there?
If you are capable enough to hack appache the choice of target makes no sense.
My best security layer is that one first has to even find my websites. If you do there are plenty of better targets among them. From the business end however the most secure look the least secure.
It's a shared hosting account, if I try to send bulk email they will immediately unplug it.
That leaves only the glory of pwning the last instance of some obscure cms?
It would probably make me laugh? Everything will be back up within a week. Nothing of value is lost.
Like you said, shared hosting and low value server so you don't mind either way.
My point though, in my prior comment, was attack surface.
With PHP you have outdated code in the ORM/MVC/whatever. Then you have your code. At least with only a web server and static HTML, and entire litany, and the most likely part to get compromised, is not there any more.
In my 30+ years of experience dealing with people getting compromised, it's always been some asshat not doing security updates (eg, using a distro and updating daily). Or worse, just compiling stuff then not updating builds on a daily or weekly basis.
Outside of that, it's been bad PHP code. Or perl. Or whatever.
I think once out of all the times I've been called to clean up a mess, has it been the web server itself. Bearing in mind "I didn't update my OS/web server for a year, and now I got hacked!!" isn't "it was the web server", it's "dumbass didn't do security updates".
Anyhow.
You're not wrong, yes everything is vulnerable. But PHP + framework + PHP code bugs == 9999, web server == 1 of the time.
If it's shared hosting, still a problem, just not theirs.
You're running the wrong stack - I, myself, find that simply having a static file website is enough to cut down on the traffic.
You need to run something other than static file serving to get bot attention.
You can watch a live stream of it here: https://bencevans.io/security/certificate-stream
They're either using Passive DNS logs or a historical dataset.
For my personal website it’s 10x more bots but I barely notice because it’s a few pages.
For the record I thought I had this site behind basic auth.
The scam of "everyone should have SSL" right here, ladies and gentlemen.
New hotness: DNS-less
See? It's quite short.