WhatWeb report for https://nextcloud.lan.ddnsgeek.com:443
Status    : 302 Found
Title     : <None>
IP        : 167.179.167.166
Country   : NEW ZEALAND, NZ

Summary   : Apache[2.4.66], Cookies[__Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2], HTTPServer[Debian Linux][Apache/2.4.66 (Debian)], HttpOnly[__Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2], PHP[8.3.30], RedirectLocation[https://nextcloud.lan.ddnsgeek.com/index.php/login], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-robots-tag], X-Frame-Options[SAMEORIGIN], X-Powered-By[PHP/8.3.30], X-XSS-Protection[1; mode=block]

Detected Plugins:
[ Apache ]
	The Apache HTTP Server Project is an effort to develop and
	maintain an open-source HTTP server for modern operating
	systems including UNIX and Windows NT. The goal of this
	project is to provide a secure, efficient and extensible
	server that provides HTTP services in sync with the current
	HTTP standards.

	Version      : 2.4.66 (from HTTP Server Header)
	Google Dorks: (3)
	Website     : http://httpd.apache.org/

[ Cookies ]
	Display the names of cookies in the HTTP headers. The
	values are not returned to save on space.

	String       : ocexfs76yoe2
	String       : oc_sessionPassphrase
	String       : ocexfs76yoe2
	String       : __Host-nc_sameSiteCookielax
	String       : __Host-nc_sameSiteCookiestrict
	String       : ocexfs76yoe2

[ HTTPServer ]
	HTTP server header string. This plugin also attempts to
	identify the operating system from the server header.

	OS           : Debian Linux
	String       : Apache/2.4.66 (Debian) (from server string)

[ HttpOnly ]
	If the HttpOnly flag is included in the HTTP set-cookie
	response header and the browser supports it then the cookie
	cannot be accessed through client side script - More Info:
	http://en.wikipedia.org/wiki/HTTP_cookie

	String       : __Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2

[ PHP ]
	PHP is a widely-used general-purpose scripting language
	that is especially suited for Web development and can be
	embedded into HTML. This plugin identifies PHP errors,
	modules and versions and extracts the local file path and
	username if present.

	Version      : 8.3.30
	Google Dorks: (3)
	Website     : http://www.php.net/

[ RedirectLocation ]
	HTTP Server string location. used with http-status 301 and
	302

	String       : https://nextcloud.lan.ddnsgeek.com/index.php/login (from location)

[ Strict-Transport-Security ]
	Strict-Transport-Security is an HTTP header that restricts
	a web browser from accessing a website without the security
	of the HTTPS protocol.

	String       : max-age=15552000; includeSubDomains; preload

[ UncommonHeaders ]
	Uncommon HTTP server headers. The blacklist includes all
	the standard headers and many non standard but common ones.
	Interesting but fairly common headers should have their own
	plugins, eg. x-powered-by, server and x-aspnet-version.
	Info about headers can be found at www.http-stats.com

	String       : content-security-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-robots-tag (from headers)

[ X-Frame-Options ]
	This plugin retrieves the X-Frame-Options value from the
	HTTP header. - More Info:
	http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
	aspx

	String       : SAMEORIGIN

[ X-Powered-By ]
	X-Powered-By HTTP header

	String       : PHP/8.3.30 (from x-powered-by string)

[ X-XSS-Protection ]
	This plugin retrieves the X-XSS-Protection value from the
	HTTP header. - More Info:
	http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
	aspx

	String       : 1; mode=block

HTTP Headers:
	HTTP/1.1 302 Found
	Content-Length: 0
	Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-eJJaUYSl69LnzUT5f2oen13g5dGL7ymBpryYUsbS1rM='; style-src 'self' 'unsafe-inline'; frame-src *; img-src * data: blob:; font-src 'self' data:; media-src *; connect-src *; object-src 'none'; base-uri 'self';
	Content-Type: text/html; charset=UTF-8
	Date: Tue, 14 Apr 2026 03:52:32 GMT
	Location: https://nextcloud.lan.ddnsgeek.com/index.php/login
	Referrer-Policy: no-referrer
	Server: Apache/2.4.66 (Debian)
	Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
	Set-Cookie: oc_sessionPassphrase=5pTvnvYZRBKLnd46XMg0XJgoZATFmwg0xpb9U1MWOfbLENZfrRG142BX4xAg7bm56hCNDQECmNcTK4g1NdWTqtlGZEsFXybcLKF2X9emXfyh%2BvINw27UVedM9bAdvRzR; path=/; secure; HttpOnly; SameSite=Lax
	Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
	Set-Cookie: __Host-nc_sameSiteCookielax=true; path=/; httponly;secure; expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=lax
	Set-Cookie: __Host-nc_sameSiteCookiestrict=true; path=/; httponly;secure; expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=strict
	Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
	Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
	X-Content-Type-Options: nosniff
	X-Frame-Options: SAMEORIGIN
	X-Permitted-Cross-Domain-Policies: none
	X-Powered-By: PHP/8.3.30
	X-Robots-Tag: noindex, nofollow
	X-Xss-Protection: 1; mode=block
	Connection: close

WhatWeb report for https://nextcloud.lan.ddnsgeek.com/index.php/login
Status    : 200 OK
Title     : ,Login – Nextcloud
IP        : 167.179.167.166
Country   : NEW ZEALAND, NZ

Summary   : Cookies[ocexfs76yoe2], HTML5, HTTPServer[Debian Linux][Apache/2.4.66 (Debian)], HttpOnly[ocexfs76yoe2], Open-Graph-Protocol[website], PHP[8.3.30], Script, Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,feature-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-request-id,x-robots-tag], X-Frame-Options[SAMEORIGIN], X-Powered-By[PHP/8.3.30], X-XSS-Protection[1; mode=block]

Detected Plugins:
[ Cookies ]
	Display the names of cookies in the HTTP headers. The
	values are not returned to save on space.

	String       : ocexfs76yoe2

[ HTML5 ]
	HTML version 5, detected by the doctype declaration


[ HTTPServer ]
	HTTP server header string. This plugin also attempts to
	identify the operating system from the server header.

	OS           : Debian Linux
	String       : Apache/2.4.66 (Debian) (from server string)

[ HttpOnly ]
	If the HttpOnly flag is included in the HTTP set-cookie
	response header and the browser supports it then the cookie
	cannot be accessed through client side script - More Info:
	http://en.wikipedia.org/wiki/HTTP_cookie

	String       : ocexfs76yoe2

[ Open-Graph-Protocol ]
	The Open Graph protocol enables you to integrate your Web
	pages into the social graph. It is currently designed for
	Web pages representing profiles of real-world things .
	things like movies, sports teams, celebrities, and
	restaurants. Including Open Graph tags on your Web page,
	makes your page equivalent to a Facebook Page.

	Version      : website

[ PHP ]
	PHP is a widely-used general-purpose scripting language
	that is especially suited for Web development and can be
	embedded into HTML. This plugin identifies PHP errors,
	modules and versions and extracts the local file path and
	username if present.

	Version      : 8.3.30
	Google Dorks: (3)
	Website     : http://www.php.net/

[ Script ]
	This plugin detects instances of script HTML elements and
	returns the script language/type.


[ Strict-Transport-Security ]
	Strict-Transport-Security is an HTTP header that restricts
	a web browser from accessing a website without the security
	of the HTTPS protocol.

	String       : max-age=15552000; includeSubDomains; preload

[ UncommonHeaders ]
	Uncommon HTTP server headers. The blacklist includes all
	the standard headers and many non standard but common ones.
	Interesting but fairly common headers should have their own
	plugins, eg. x-powered-by, server and x-aspnet-version.
	Info about headers can be found at www.http-stats.com

	String       : content-security-policy,feature-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-request-id,x-robots-tag (from headers)

[ X-Frame-Options ]
	This plugin retrieves the X-Frame-Options value from the
	HTTP header. - More Info:
	http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
	aspx

	String       : SAMEORIGIN

[ X-Powered-By ]
	X-Powered-By HTTP header

	String       : PHP/8.3.30 (from x-powered-by string)

[ X-XSS-Protection ]
	This plugin retrieves the X-XSS-Protection value from the
	HTTP header. - More Info:
	http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
	aspx

	String       : 1; mode=block

HTTP Headers:
	HTTP/1.1 200 OK
	Cache-Control: no-cache, no-store, must-revalidate
	Content-Encoding: gzip
	Content-Length: 5801
	Content-Security-Policy: default-src 'none';base-uri 'none';manifest-src 'self';script-src 'nonce-SVXVLb4Re1+OOOXuQ3YRupmmoh1cwSYDPAn4J796nvU=';script-src-elem 'strict-dynamic' 'nonce-SVXVLb4Re1+OOOXuQ3YRupmmoh1cwSYDPAn4J796nvU=';style-src 'self' 'unsafe-inline';img-src 'self' data: blob: https://*.tile.openstreetmap.org;font-src 'self' data:;connect-src 'self';media-src 'self';frame-src 'self';frame-ancestors 'self';form-action 'self'
	Content-Type: text/html; charset=UTF-8
	Date: Tue, 14 Apr 2026 03:53:08 GMT
	Feature-Policy: autoplay 'self';camera 'none';fullscreen 'self';geolocation 'none';microphone 'none';payment 'none'
	Referrer-Policy: same-origin
	Server: Apache/2.4.66 (Debian)
	Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
	Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
	X-Content-Type-Options: nosniff
	X-Frame-Options: SAMEORIGIN
	X-Permitted-Cross-Domain-Policies: none
	X-Powered-By: PHP/8.3.30
	X-Request-Id: xJN1PJW80BokVwJXwvnU
	X-Robots-Tag: noindex, nofollow
	X-Xss-Protection: 1; mode=block
	Connection: close


