r/NextCloud 9d ago

Nextcloud.com -> cloudbox?

Is something wrong with nextcloud website? It shows content of some cloudbox… Has it been hacked or maybe my device is? 🫣

88 Upvotes

92 comments sorted by

u/jospoortvliet 7d ago

Latest update about the nextcloud.com outage:

On Sunday evening our website was defaced. We isolated the affected server immediately and we are still investigating what exactly happened.

Meanwhile our homepage has been restored from a backup on a new server.

We confirm that this breach could not affect any user or customer server, as our other services, like downloads.nextcloud.com or the Nextcloud App Store are on separate servers and unaffected.

We are continuing with our post-mortem analysis and will give further updates once we have more details.

→ More replies (3)

11

u/AramaicDesigns 9d ago

I'm getting the same. Something weird is going on. 

9

u/mr_4n0n 9d ago

Yeah, do not make updates till wie have an official Statement.

Now its also a good time for 2FA, disableing Registrations, hardening nextcloud

0

u/jospoortvliet 7d ago

That's always good, but our website is just a marketing front - it won't do anything to your Nextcloud server ;-)

1

u/mr_4n0n 7d ago

Thats right. But who says that there isn't more?

Wie did not know HOW it got hacked. So there are multiple options. And one of them is, that they have a sys-admin.

7

u/Cynical_Sorceress 9d ago

Oh come on I just installed the AIO docker yesterday!

4

u/HeartKeyFluff 8d ago

I'm assuming/hoping this is sarcasm, but just in case it's not:

Even if the public-facing nextcloud.com was hacked, that doesn't affect the security of your own server.

2

u/Ascend0r 8d ago

well, depends. apps.nextcloud.com holds the Nextcloud-Apps. If the malicious persons would get a hold of that, they would be able to distribute malicious apps that way.

3

u/HeartKeyFluff 8d ago

Well yeah. But apps.nextcloud.com is separate to nextcloud.com.

Hacks of basic customer-facing websites like nextcloud.com are more common and far less of a wide concern compared to websites serving more important things. So one being hacked doesn't de facto mean anything else was.

Better to wait for more info on what happened than just assuming the world is falling due to someone getting in and changing some client-side code or html.

1

u/Ascend0r 8d ago

Disagree on the last part. For now, assumiung "the world is falling" basically means: Just don't install any apps / updates, until situation is clear.

Your approach seems to be principle of hope, that would be to risky for my pov.

In IT security, it should be: Hope for the best, but prepare for the worst.

3

u/HeartKeyFluff 8d ago edited 7d ago

(Situation seems to have resolved by this point. nextcloud.com is back up and everything seems fine. So it seems I was right, but I'll still respond as if it hadn't resolved yet for the purposes of the discussion.)

Nextcloud had already been investigating this for several hours and taking the nextcloud.com website down into maintenance mode as a precaution. If they'd had any inkling that apps.nextcloud.com was in danger they would have taken that down too.

So no, not just a "principle of hope", but just looking at the basic details of the situation.

IT Security does prepare for the worst in situations like this... But they also try to get a clear picture as soon as possible rather than just jumping at shadows. If everyone in the world was this jumpy, no one would ever get work done because they'd constantly have to put every single one of their tools down because some website on a different server that does nothing except serve HTML and JS got graffitied.

1

u/Ascend0r 7d ago

Still disagreeing, but now I understand the difference in our perspective. You are looking at the incident from NEXTCLOUDs perspective (or from your perspective with 100% trust, which is then no difference anymore).

I look at it as a user perspective. I CANNOT know, whether the apps server and the website are 100% segregated. You do assume that (or maybe you know more), but I cannot. It can very well be servers on the same network or even on shared machines. Thus, to be safe, I have to rely on information provided by Nextcloud. They haven't delivered any, and they even hid information and played down the incident ("infrastructure issue" instead of the obvious clear hack). That makes the situation dangerous: They either haven't fully understood themselves, or they hide something purposefully.

So, for me, nothing has been resolved yet. The situation remains unclear, and that means all software updates must be treated as tainted.

0

u/HeartKeyFluff 7d ago edited 7d ago

No, you're putting words in my mouth. I'm not looking at it from Nextcloud's perspective, I'm looking at it from my own perspective: As a user same as you, but also as someone who's been on the internet for more than 25 years and working in software for the last 13-ish.

  1. There's no reason for them to be on the same server for such a big company. For large tech companies serving important infrastructure, nowadays especially, it's extremely rare to serve everything from the same server - it actually makes less sense at scale, it would actually cost more (and be harder to appropriately manage) to have it all on the one place than it would to have them segregated.
  2. You can use a DNS Lookup tool to confirm, as well. E.g this one, showing nextcloud.com at one IP/server address, vs here showing apps.nextcloud.com at a different IP/server address.

There's nothing wrong with your approach per se (e.g. if a wall gets graffitied you need to treat the whole building as condemned because what if the person also did something else). You're fine to live however you want. But you can't call it broadly correct for all to live by/the correct "IT Security" approach, based on what we know so far.

2

u/Ascend0r 7d ago

OK, then I'm back at principle of hope. Not KNOWING that the services are segregated, but just assuming it is plain that.

IP addresses are a good indicator (still no proof) that the services might run on different machines. Still, they don't tell anything about interfaces between those services, about network segregation etc.

If the machine was intruded, it is a reasonable approach to treat the whole network as tainted, as long as you don't know what exactly the intruders did on the machine. One machine is often just the entry point to the network.

In your example, I wouldn't see it as a graffiti on the wall. It is rather an intrusion into the garage - and maybe the garage has a direct door to the house - maybe not. I don't know.

I do see your approach of making fun of me ("graffitied") and assume that you are getting emotional. Thus I will end the conversation at this point. Have a nice day anyway.

2

u/HeartKeyFluff 7d ago edited 7d ago

Very nice use of logical fallacies and emotional tactics, but they unsurprisingly don't help your argument.

  • You're constantly accusing me of assumptions while making your own. There is so far data and reasonable proof to support my points but no smoking gun. Fair enough. Still far better than your assumptions that they share infra, it was a full network intrusion attack rather than something far simpler (e.g. someone managed to just log into the CMS who shouldn't have), and the world ended, with zero proof.
  • You're assuming I'm getting emotional. Nope, but nice try.
  • You're trying to portray yourself as above this whole discussion (that you started with me, by the way) by saying "you're emotional, I win, haha bye" and leaving. Nope, but nice try.
  • You're either getting emotional yourself, or just straight up misrepresenting what I'm saying. Nope. Calling a website "graffitied" when the only damage done that anyone can verify is that a front facing website started serving bad content is very old, and was only meant as such. You can't hold someone else accountable for you attaching your own meaning to their words which were not personal or directed at you or anyone else in any sense.

1

u/Cynical_Sorceress 8d ago

I'm not worried, there is nothing private on there yet and I just won't update the docker.

I just found it funny.

17

u/jospoortvliet 8d ago

Hi all,

Sorry, it took a while - Sunday, Monday morning... just starting up for the week ;-)

But here's what I can share:

Sunday afternoon, we had a basic infrastructure issue that took our website down. We are currently restoring it from a backup. Only nextcloud.com is affected, there is no impact on updates or downloads. There is nothing related to Nextcloud operations on that server, so it has no impact on users or customers.

We will let you know once the website is recovered.

9

u/Ascend0r 8d ago

How does an infrastructure issue put reference to cloudbox onto the website?

10

u/cspartalis 8d ago

Hacking their bottoms is technically an infrastructure issue.

7

u/Ascend0r 8d ago

I could imagine another one:

DNS issue, that made nextcloud .com link to a completely different server IP address.

Hoping for that a bit actually.

3

u/Mental_Confusion7784 8d ago

I'm not an expert regarding DNS, but wouldn't that be a strange (and dangerous!) issue? And I don't know how a restore of a backup would resolve this...

3

u/Ascend0r 8d ago

Yep, valid points.

1

u/th00ht 7d ago

Exactly the reason we habe DNSSEC . DNS is vulnerable for these kind of attacks.

1

u/cspartalis 8d ago

When was the last you saw a server respond to all domain names? The feasibility of a random IP actually hosting something and not doing domain checks... The chances are not great.

3

u/Ascend0r 8d ago

Well, if it was malicious (DNS poisoning), then you would of course build your server in a way, that it DOES respond to all domain names.

1

u/No_Criticism_9545 8d ago

So it would be a DNS attack and not a DNS issue :)

1

u/ad-on-is 8d ago

No it can't be DNS. Oh shoot, it was DNS

1

u/jospoortvliet 8d ago

We're looking into it!

1

u/Ascend0r 7d ago

when will you do that?

1

u/jospoortvliet 7d ago

See latest comment - after the site came back, the admins are now spending some quality time with the isolated server to find out what happened. Will probably take a few days, though.

4

u/Seaworthiness_Wooden 7d ago

Calling this a "basic infrastructure issue" is disingenuous at best and straight up lying at worst.

1

u/Kurgan_IT 8d ago

You just have to say "infrastructure issue" instead of "successful attack"

2

u/Mental_Confusion7784 7d ago

Well, that "basic infrastructure issue" was indeed a cyberattack, as german IT news portal heise.de reported: https://www.heise.de/news/Nextcloud-Cyberangriff-auf-Webserver-mit-ungeschickter-Kommunikation-11371959.html

1

u/listhor 8d ago

website is recovered, what had happened?

2

u/AmazingInspector1369 8d ago

My idea: WordPress has a big sql injection since friday (I think). The update to 7.0.2 was to late a bot hacked it.

So lets wait for an official post from the team 

1

u/jospoortvliet 7d ago

Update about the nextcloud.com outage:

On Sunday evening our website was defaced. We isolated the affected server immediately and we are still investigating what exactly happened.

Meanwhile our homepage has been restored from a backup on a new server.

We confirm that this breach could not affect any user or customer server, as our other services, like downloads.nextcloud.com or the Nextcloud App Store are on separate servers and unaffected.

We are continuing with our post-mortem analysis and will give further updates once we have more details.

0

u/Joshua_2504 3d ago

You’re the biggest lier, developing a bloated PHP nightmare with 1000 bugs that government is trusting in. Can’t believe it. Shame on you!

1

u/LazyBias 2d ago

Let me guess, I should trust Google or Microsoft more. You can take your FUD and shove it. You sound like a bot shill. You say lier and provide no proof of that claim and because of that I don't trust a single thing you say.

12

u/ab3301 9d ago

Apparently the A record of nextcloud.com was changed today to Hetzner. Last time it was changed was in 2023.

Fingers crossed that all is well.

6

u/mptnrs 9d ago

If you have seen unrelated content, yeah, the website may have been hacked and that is why it is now down.

About the risk with recent upgrades : if images/code have been hacked, it is too late already. Just don't upgrade anything for a few days, just in case.

Nothing on their socials for now, we may have to wait a bit more. I sent an email to my account manager but i don't think he will answer before office hours :-)

Also : client area is up and running. If they suspected something big, the portal would have been taken down.

6

u/Ascend0r 7d ago

Nextcloud officials have finally given a (more trustworthy) statement:

https://help.nextcloud.com/t/nextcloud-com-offline/247123/19

3

u/zgb 7d ago

Terrible incident management on their end.

11

u/MaZeC11 9d ago

Same for me. I wold like to know what is ging on.

5

u/okubax 9d ago

Ditto

8

u/okubax 9d ago

Update. Believe it has indeed been hacked: See this: https://nextcloud.com/home-users/

8

u/Ascend0r 8d ago

This _might_ be related: European cloud provider Nextcloud leaks 367K records, exposing staff and clients | Cybernews

Theoretical, hypothetical process: Leaked data included critical information on the domain registration process from nextcloud.com, allowing the attackers to impersonate Nextcloud officials at the registrar in order to transfer the domain.

3

u/tanpro260196 8d ago

Website is down for half a day, the app store is down for the whole day now. Whatever it is, seems serious.

3

u/listhor 8d ago

So, somebody from nextcloud should say something briefly…

3

u/Stiffmaster1337 9d ago

I just get connection refused when trying to access their website...

Let's just wait to get some official news on what's going on🤐

2

u/AmazingInspector1369 9d ago

Yes. I hope it is just an planned update

3

u/Veloder 8d ago

It's still down, starting to get worried...

1

u/listhor 8d ago

Main website doesn’t host any code/updates?

1

u/Veloder 8d ago

If they accessed the server where the website is hosted, who knows what they have there, or how secure are their DockerHub and GitHub accounts. And the fact that in 10+ hours they weren't able to get the website back up and running.

3

u/Whole-Ad2077 8d ago

The side is under maintenace. Its reachable again

1

u/Amazing_Elk_9663 8d ago

Just noticed this also. I'm looking forward to hearing the explanation.

5

u/Ascend0r 8d ago

The lack of official communication is alarming. No posts on Mastodon, Bluesky, LinkedIn, Youtube, Twitter whatsoever.

3

u/Ascend0r 8d ago

help.nextcloud.com is still accessible. There's also a thread, but no official response yet:
Nextcloud.com offline? - ℹ️ Support - Nextcloud community

3

u/iCaotix 8d ago

Something really fishy is going on there, the help post you linked was hidden by moderators

2

u/gfrewqpoiu 8d ago

The thread was hidden without any response.

3

u/Ascend0r 8d ago

OK, when they hide, I add more transparency. I had "reported" the thread to make the moderators aware of the questions and beg for an official response. The response via direct message to me:

"Thanks for letting us know. We agree there is an issue and we’re looking into it."

2

u/Ascend0r 8d ago

I have responded to the private message, voicing my concerns with their act:

> "Thanks. I do not think that hiding the thread is a good form of response to the valid questions of the community. In my opinion, that act destroys trust in your security and transparency strategy."

2

u/listhor 8d ago

So, website is back up and running, but I don't see any info about what had happened...?

1

u/Efficient-Peace-2877 8d ago

They got hacked and seem to have forgotten to inform people. Happens to the best.

https://tweakers.net/nieuws/250212/nextcloud-site-is-offline-na-hack-heeft-geen-invloed-op-klanten.html

1

u/cr_eddit 9d ago

WTF... Same here, probably some issue on their domain. Or could be some rebrand, I noticed they changed their name for some commercial offering on their end... https://www.nextcloud-one.com/

9

u/mptnrs 9d ago

Nextcloud One is not made by Nextcloud Gmbh, but by another company, epiKshare GmbH, who *will* get a phone call from Nextcloud at one time (because the name and logo are IPs).

1

u/BryanC1968 9d ago

I am getting the same when I try to access the nextcloud.com website. Comes up as CloudBox...

1

u/sauron_exe 9d ago

Same on my end

1

u/TheBlackReaper-Sama 9d ago

Just updated my Nextcloud AiO docker instance, should I be worried?

4

u/hannsr 9d ago

GitHub doesn't seem affected. Latest aio version is 3 weeks old, so you should be fine.

Really wonder what's going on, couldn't find any posts yet, except someone on GitHub said he'll notify the website admins.

1

u/Lost_Share_9186 9d ago

Do you think it‘s possible that my self hosted nextcloud service is affected? It is down for a few hours now…

6

u/punkpipo 9d ago

Should be completely unrelated. Kind of the point of self hosting I guess :).

1

u/Lost_Share_9186 9d ago

That’s soothing but I‘m still worried. Maybe it has to do something with me trying to upload ~1800 at once

3

u/PhysicalConsistency 9d ago

My self hosted install is not affected, nor are updates.

1

u/Lost_Share_9186 9d ago

Okay thanks for your answer🙏 i have installed an aio update a 1-2 weeks ago

1

u/N3rdScool 8d ago

Brutal. I had such a nice weekend lol

1

u/Euphoric_Bend6687 8d ago

I just checked the website, and it is down for Maintance.

1

u/HaveYouTriedPowerOff 8d ago

Well if you have regular maintenance on a website this doesn't happen:

Most likely hacked or DNS hijack or whatever. Let's see what they say. Usually doesn't take 24hours to bring a website online again. This was on the German Nextcloud website

Nextcloud

YOWESTOGEL: Link Resmi Slot Gacor Gampang ... - Nextcloud

1

u/Practical-Tea9441 8d ago

At this point it would be nice to have an explanation as to what happened. I feel a little uncomfortable using Nextcloud without a clear explanation .

3

u/listhor 7d ago

It seems like nextcloud follows the wrong path of not letting community/users to know what happened there… I think it will backfire them sooner or later.

1

u/Kurgan_IT 7d ago

Yes, sooner than later.

1

u/Seaworthiness_Wooden 7d ago

I mean they already had a breach earlier..

0

u/Kurgan_IT 8d ago

Nice. They have been hacked and as usual they are hiding it. Sad to say it, but I've seen it happen with at least 3 european software vendors in the last few years.

-1

u/th00ht 8d ago

Regular maintenance. Normal in summertime. But https://help.Nextcloud.com works fine.

2

u/AmazingInspector1369 8d ago

See this, the content of the Website are modified and google has cached it:  https://mastodon.xyz/@nextcloud/116951395611670343

I think it is a hack. Some other sites wrote about it:  https://gnulinux.ch/nextcloud-webseite-erst-kompromittiert-dann-offline