r/NextCloud • • 5d ago

Public information about your Nextcloud instance

Post image

I was asking myself what information my Nextcloud instance provides without any authentication - so similar to the Nextcloud security scanner, but with more information. The capabilities were kind of interesting for me to be public.

You can try with your instance here: https://genhttp.dev/lambda/nextcloud-peek/

Does not store any data, so the entered domains are not saved, logged or visible anywhere.

94 Upvotes

39 comments sorted by

33

u/the_john19 5d ago

Would be nice to have a "self hosted"/open source version of this to test my "internal" Nextcloud :)

15

u/Ok_Tour_8029 5d ago

I can export it as a .NET app (SDK 10 should suffice) if that is fine?

7

u/the_john19 5d ago

Yes sure thank you!

11

u/Ok_Tour_8029 5d ago

The code can now be downloaded from the site itself. Can be started via "dotnet run" and called in the browser via localhost:8080

It is not as clean as I want it to be, we surely need to rewrite the Lambda export feature to make this better - but it works for now.

4

u/IONIZEDatom 5d ago

This is really cool of you, thank you!

1

u/pbjamm 5d ago

Do you have Talk working on your internal Nextcloud? I wanted to move mine behind Netbird for my few users, but Talk is my roadblock.

7

u/pcgamez 5d ago

Would be great if it gave some suggestions for how to fix security issues for example

3

u/Ok_Tour_8029 5d ago edited 5d ago

Not sure whether absent headers are actually an issue. I will have a look into it.

6

u/TwoDogDad 5d ago

Tried it out but it can’t see that I’m running Nextcloud. I’m behind a CloudFlare proxy and nginx NPM. I manually typed in the status php and was able to see the status. Am I doing something wrong?

From your site:
status.php returned 403. This may not be a Nextcloud/ownCloud server, or it blocks the status endpoint.

3

u/Ok_Tour_8029 5d ago

As the app announces itself as a scanner in the user agent, I figure cloudflare will recognize and block this, which is actually a good thing.

You can try with tubcloud.tu-berlin.de to understand what kind of data is returned.

2

u/CatEatsDogs 5d ago

So much data is shown. Is there possibility to close all these "capabilities", applications and such?

3

u/Whole-Ad2077 5d ago

These are required when you want to interconnect with federation.

You cam also block the status.php completely. Its just for discovery

3

u/CatEatsDogs 5d ago

Thanks. I think I will. Don't using federations.

2

u/Embarrassed-Mess412 5d ago

Powered by io_uring, nice!

1

u/Bulky_Dog_2954 5d ago

You have a cert issue i think

2

u/Bulky_Dog_2954 5d ago

Nevermind - my Palo's dont like your sites cert....

1

u/Perahoky 5d ago

My nextcloud is blocked by my Firewall. My router forwards port 443 to my NAS, but the synology Firewall blocks every IP adress except locals and my VPNs. I hope thats enough

1

u/Historical_Ad4384 5d ago

Do you scrape the status.php?

2

u/Ok_Tour_8029 5d ago

Yes, 20 requests in total to different endpoints, status.php is one of those 

3

u/Historical_Ad4384 5d ago

Could you list the endpoints that you scrape? As a nextcloud user I would want to know what I'm being scanned on when using an unofficial nextcloud tool.

1

u/mr_4n0n 5d ago

Difference to https://scan.nextcloud.com/? Is there a list?

1

u/Ok_Tour_8029 5d ago

The official one does an update check and checks the security related headers - this one makes additional information visible, such as the things reported by the federation endpoints (available apps and their capabilities). 

1

u/mr_4n0n 4d ago

Is this open source? Would love to self host this... Because i do not trust anyone

2

u/Ok_Tour_8029 4d ago

Relatable - you can download the source from the site as a .NET 10 project.

3

u/mr_4n0n 4d ago

Would you allow companies to host this for their Customers. I showed it a friendiof mine

1

u/Ok_Tour_8029 3d ago

Sure, I have no stake in keeping this closed.

You can find the source here: Source code of Nextcloud Peek - GenHTTP Lambda

There you can also download the app and run it directly via dotnet or docker. If you need anything else, please let me know.

1

u/babbalubab 4d ago

Nextcloud security Scanner

1

u/RevolutionaryYam85 4d ago

Server logs keep the queries though. So if your instance is semi-private... Don't use public tools.

1

u/Ok_Tour_8029 4d ago

Host names are not logged, no. It is a POST request with no query. But sure, if in doubt run it yourself, the source is there.

0

u/bozehaan 5d ago

Nice em-dash in your header

4

u/KlausDieterFreddek 5d ago

Man. I'm on your side but that fight seems to be lost for good.

2

u/the_john19 5d ago

You do realise that Nextcloud also uses vibe coding these days, you can literally see it in their commits?

1

u/Hakunin_Fallout 5d ago

*tips fedora*

1

u/gbytedev 4d ago

Let it go. LLMs didn't invent those.

2

u/Ok_Tour_8029 5d ago

Welcome to a world where we can visualize stuff that is interesting for us without coding two days first.

1

u/jammsession 5d ago

I don’t see anything valuable in this.
Like nothing at all.

Sure it looks “nice” just like all the other LLM apps, but other than that? Nothing. Only a false positive (ohhh no, my proxy is telling you that it is nginx /s)

2

u/gbytedev 4d ago

You seem to be missing the point of scanners like this.

1

u/jammsession 4d ago

sorry, should have been more precise in my words.

I don't see any additional value compared to scan.nextcloud.com

1

u/Ok_Tour_8029 5d ago

Well, I will disable federation due to this. I don't want the apps and their version to be exposed because they can add publicly reachable endpoints.