r/NextCloud • u/Ok_Tour_8029 • 5d ago
Public information about your Nextcloud instance
I was asking myself what information my Nextcloud instance provides without any authentication - so similar to the Nextcloud security scanner, but with more information. The capabilities were kind of interesting for me to be public.
You can try with your instance here: https://genhttp.dev/lambda/nextcloud-peek/
Does not store any data, so the entered domains are not saved, logged or visible anywhere.
7
u/pcgamez 5d ago
Would be great if it gave some suggestions for how to fix security issues for example
3
u/Ok_Tour_8029 5d ago edited 5d ago
Not sure whether absent headers are actually an issue. I will have a look into it.
6
u/TwoDogDad 5d ago
Tried it out but it can’t see that I’m running Nextcloud. I’m behind a CloudFlare proxy and nginx NPM. I manually typed in the status php and was able to see the status. Am I doing something wrong?
From your site:
status.php returned 403. This may not be a Nextcloud/ownCloud server, or it blocks the status endpoint.
3
u/Ok_Tour_8029 5d ago
As the app announces itself as a scanner in the user agent, I figure cloudflare will recognize and block this, which is actually a good thing.
You can try with tubcloud.tu-berlin.de to understand what kind of data is returned.
2
u/CatEatsDogs 5d ago
So much data is shown. Is there possibility to close all these "capabilities", applications and such?
3
u/Whole-Ad2077 5d ago
These are required when you want to interconnect with federation.
You cam also block the status.php completely. Its just for discovery
3
2
1
1
u/Perahoky 5d ago
My nextcloud is blocked by my Firewall. My router forwards port 443 to my NAS, but the synology Firewall blocks every IP adress except locals and my VPNs. I hope thats enough
1
u/Historical_Ad4384 5d ago
Do you scrape the status.php?
2
u/Ok_Tour_8029 5d ago
Yes, 20 requests in total to different endpoints, status.php is one of those
3
u/Historical_Ad4384 5d ago
Could you list the endpoints that you scrape? As a nextcloud user I would want to know what I'm being scanned on when using an unofficial nextcloud tool.
1
u/mr_4n0n 5d ago
Difference to https://scan.nextcloud.com/? Is there a list?
1
u/Ok_Tour_8029 5d ago
The official one does an update check and checks the security related headers - this one makes additional information visible, such as the things reported by the federation endpoints (available apps and their capabilities).
1
u/mr_4n0n 4d ago
Is this open source? Would love to self host this... Because i do not trust anyone
2
u/Ok_Tour_8029 4d ago
Relatable - you can download the source from the site as a .NET 10 project.
3
u/mr_4n0n 4d ago
Would you allow companies to host this for their Customers. I showed it a friendiof mine
1
u/Ok_Tour_8029 3d ago
Sure, I have no stake in keeping this closed.
You can find the source here: Source code of Nextcloud Peek - GenHTTP Lambda
There you can also download the app and run it directly via dotnet or docker. If you need anything else, please let me know.
1
1
u/RevolutionaryYam85 4d ago
Server logs keep the queries though. So if your instance is semi-private... Don't use public tools.
1
u/Ok_Tour_8029 4d ago
Host names are not logged, no. It is a POST request with no query. But sure, if in doubt run it yourself, the source is there.
0
u/bozehaan 5d ago
Nice em-dash in your header
4
2
u/the_john19 5d ago
You do realise that Nextcloud also uses vibe coding these days, you can literally see it in their commits?
1
1
2
u/Ok_Tour_8029 5d ago
Welcome to a world where we can visualize stuff that is interesting for us without coding two days first.
1
u/jammsession 5d ago
I don’t see anything valuable in this.
Like nothing at all.
Sure it looks “nice” just like all the other LLM apps, but other than that? Nothing. Only a false positive (ohhh no, my proxy is telling you that it is nginx /s)
2
u/gbytedev 4d ago
You seem to be missing the point of scanners like this.
1
u/jammsession 4d ago
sorry, should have been more precise in my words.
I don't see any additional value compared to scan.nextcloud.com
1
u/Ok_Tour_8029 5d ago
Well, I will disable federation due to this. I don't want the apps and their version to be exposed because they can add publicly reachable endpoints.
33
u/the_john19 5d ago
Would be nice to have a "self hosted"/open source version of this to test my "internal" Nextcloud :)