Files
autorecon/results/nextcloud.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt
T
2026-04-14 17:49:38 +10:00

229 lines
13 KiB
Plaintext

# Nmap 7.99 scan initiated Tue Apr 14 03:49:00 2026 as: /usr/lib/nmap/nmap -vv --reason -Pn -T4 -sV -p 443 "--script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN /root/results/nextcloud.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/nextcloud.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml nextcloud.lan.ddnsgeek.com
Nmap scan report for nextcloud.lan.ddnsgeek.com (167.179.167.166)
Host is up, received user-set (0.014s latency).
rDNS record for 167.179.167.166: 167-179-167-166.a7b3a7.bne.nbn.aussiebb.net
Scanned at 2026-04-14 03:49:13 UTC for 503s
PORT STATE SERVICE REASON VERSION
443/tcp open ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)
| http-waf-detect: IDS/IPS/WAF detected:
|_nextcloud.lan.ddnsgeek.com:443/?p4yl04d3=<script>alert(document.cookie)</script>
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
|_http-csrf: Couldn't find any CSRF vulnerabilities.
| ssl-cert: Subject: commonName=nextcloud.lan.ddnsgeek.com
| Subject Alternative Name: DNS:nextcloud.lan.ddnsgeek.com
| Issuer: commonName=R13/organizationName=Let's Encrypt/countryName=US
| Public Key type: rsa
| Public Key bits: 4096
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-04-10T22:57:14
| Not valid after: 2026-07-09T22:57:13
| MD5: 3e9f 313a b74d 382e 83fc 5f1a 5a53 e40b
| SHA-1: 1937 4753 629c 2c83 886f ec53 de7e 0a3c de34 7039
| SHA-256: 3c52 054a efae 0d1d 5cf0 8226 e0ae 7ad0 478a 8c85 f5e7 a963 0ddd 072d d9c5 d129
| -----BEGIN CERTIFICATE-----
| MIIGDTCCBPWgAwIBAgISBrmm2MmqMNL/bqguwka5v7ahMA0GCSqGSIb3DQEBCwUA
| MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD
| EwNSMTMwHhcNMjYwNDEwMjI1NzE0WhcNMjYwNzA5MjI1NzEzWjAlMSMwIQYDVQQD
| ExpuZXh0Y2xvdWQubGFuLmRkbnNnZWVrLmNvbTCCAiIwDQYJKoZIhvcNAQEBBQAD
| ggIPADCCAgoCggIBAMfZPcsjUERAyRB3mvCx+kUJE/5gKelvulMMV3uCdil8yiop
| 3CgXHNN1E/9hsK8/gueXU1AbcpNUrHP1clNlrMku+GuwAQF4+eulJdycXM8UBOB4
| HkWO/CljSna1EZQlPx4FhDLMSki2uLP9mgNOM1/lBQ1qPG3B3EXLKOqGlEQ/zOjg
| /gyPEBxjWA3bYZZN4oiaFHnA32ontFN7CQ7COeCJCnRpr2zAUvpRO5U5uH2cfApt
| 4gha9FQSgAj6lAqFGDrRDLqUl1oGY4HM5DWDhYiYnJ/n34hDRoWOt1D02PpCjNQf
| O4CDs+6udQN7zBNQBZiSBEtpGnQn73EFeElRvoGqZMrQFJa6/VEle+oJxdQL5JIv
| yeqILlfJqlMgAiM4rItUKl9hTtWOfTuPCGbtPx7qDG6gdD2CDxdgPfPBseiKU6DV
| sbHAs6aAv17982O0FIf4LE7vSmkVSpzafYRXdx/F5I6Zi+t7SlsC+l7cZiYMAyfU
| DP6kmO7mCGRRQmxu1Ui6hZjIWEa2VJ6epueY7GtrEmsVulna+uq+jz2vI/uk99EF
| H2NZuc/65i67UAjUllYA/58dTcC6kX6/WO5CTRsCzkhY0cCY2xGrs2i6bok50TzQ
| 90IlIpa4IK19uDunxb6i7BFY/m56lmpKkYcyNflBCOrPtBSkVpUe45skVVdRAgMB
| AAGjggInMIICIzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEw
| DAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUL6dJ4L43WNY8JT48fpK2N24MimwwHwYD
| VR0jBBgwFoAU56ufDywzoFPTXk94yLKEDjvWkjMwMwYIKwYBBQUHAQEEJzAlMCMG
| CCsGAQUFBzAChhdodHRwOi8vcjEzLmkubGVuY3Iub3JnLzAlBgNVHREEHjAcghpu
| ZXh0Y2xvdWQubGFuLmRkbnNnZWVrLmNvbTATBgNVHSAEDDAKMAgGBmeBDAECATAu
| BgNVHR8EJzAlMCOgIaAfhh1odHRwOi8vcjEzLmMubGVuY3Iub3JnLzM0LmNybDCC
| AQsGCisGAQQB1nkCBAIEgfwEgfkA9wB2AMIxfldFGaNF7n843rKQQevHwiFaIr9/
| 1bWtdprZDlLNAAABnXnSsysAAAQDAEcwRQIgFjRX18ymII+LUj3/mn40hTZc54+w
| uO66VcsD1AWz0xECIQC1XYnN8iIHf+gMkzrZSl57qZMxDvxAj0KIEL+kcIuDqwB9
| AKgmy+MKxjUSRlM/4GXxTxnZbhkIE8Qd2W15ALMSPFUnAAABnXnStdkACAAABQAG
| ZqdVBAMARjBEAiBzQI9gfXwLedWIC3sx8xgjoyD3p0Rf06uIVv7UE/IfsgIgOTTu
| GGd5gH4MWw7AmXB7oBWiZWcnJvR+gzq1RhHFtuwwDQYJKoZIhvcNAQELBQADggEB
| AG9ivSu820MYLxWacjStBZN9tZoJl6rI3E52h7pl70JXUFQ7hFr8SN0SCU9/Iz+L
| wDdrqUGC3T5lr5NeTqW1hRnsErVFGe8DygcQDEZyAwR6mi7ym1h3VwWJ+2y09We5
| euyyem+7J8l2KeaJMJZaboi9rKjp/D6nl8a7aUxD/k2WrcPfwI2pok7o+QVaHTzo
| oXUSiiowm5lU2Ir6WmDDShBc3Ddql9siUjULVqt5bUcTXXvrS2X8xItKS+Zz+J6N
| 3f6xHKzt8YFlHAoKYuRh1E7K/uKsBQ6oNEAv/fN7GJHuxbb9HHAwZJe+DTnCAPws
| 84ceLvP0DzJN/Socs95sKb4=
|_-----END CERTIFICATE-----
|_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
| http-useragent-tester:
| Status for browser useragent: 200
| Redirected To: https://nextcloud.lan.ddnsgeek.com/index.php/login
| Allowed User Agents:
| Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
| lwp-trivial
| libcurl-agent/1.0
| PHP/
| Python-urllib/2.5
| GT::WWW
| Snoopy
| MFC_Tear_Sample
| HTTP::Lite
| PHPCrawl
| URI::Fetch
| Zend_Http_Client
| http client
| PECL::HTTP
| Wget/1.13.4 (linux-gnu)
| WWW-Mechanize/1.34
| Change in Status Code:
|_ libwww: 404
| ssl-enum-ciphers:
| TLSv1.2:
| ciphers:
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A
| TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (secp256r1) - A
| compressors:
| NULL
| cipher preference: client
| warnings:
| Key exchange (secp256r1) of lower strength than certificate key
| TLSv1.3:
| ciphers:
| TLS_AKE_WITH_AES_128_GCM_SHA256 (X25519MLKEM768) - A
| TLS_AKE_WITH_AES_256_GCM_SHA384 (X25519MLKEM768) - A
| TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (X25519MLKEM768) - A
| cipher preference: server
|_ least strength: A
|_ssl-date: TLS randomness does not represent time
|_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
| http-referer-checker:
| Spidering limited to: maxpagecount=30
| https://nextcloud.lan.ddnsgeek.com:443/dist/core-common.js?v=e80d16a8-0
| https://nextcloud.lan.ddnsgeek.com:443/dist/core-login.js?v=e80d16a8-0
| https://nextcloud.lan.ddnsgeek.com:443/apps/theming/js/theming.js?v=e80d16a8-0
|_ https://nextcloud.lan.ddnsgeek.com:443/dist/core-main.js?v=e80d16a8-0
|_http-fetch: Please enter the complete path of the directory to save data in.
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-malware-host: Host appears to be clean
| http-vhosts:
| auth.lan.ddnsgeek.com : 200
|_127 names had status 404
|_http-feed: Couldn't find any feeds.
|_http-date: Tue, 14 Apr 2026 03:52:41 GMT; -3s from local time.
|_http-jsonp-detection: Couldn't find any JSONP endpoints.
|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
|_http-server-header: Apache/2.4.66 (Debian)
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
| http-security-headers:
| Strict_Transport_Security:
| Header: Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
| X_Frame_Options:
| Header: X-Frame-Options: SAMEORIGIN
| Description: The browser must not display this content in any frame from a page of different origin than the content itself.
| X_XSS_Protection:
| Header: X-XSS-Protection: 1; mode=block
| Description: The browser will prevent the rendering of the page when XSS is detected.
| X_Content_Type_Options:
| Header: X-Content-Type-Options: nosniff
| Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type.
| Content_Security_Policy:
| Header: Content-Security-Policy: default-src 'none';base-uri 'none';manifest-src 'self';script-src 'nonce-X594h5DgY3hTUT16aMu7aHJx7JGnNKQBMo8qHmmeJz4=';script-src-elem 'strict-dynamic' 'nonce-X594h5DgY3hTUT16aMu7aHJx7JGnNKQBMo8qHmmeJz4=';style-src 'self' 'unsafe-inline';img-src 'self' data: blob: https://*.tile.openstreetmap.org;font-src 'self' data:;connect-src 'self';media-src 'self';frame-src 'self';frame-ancestors 'self';form-action 'self'
| Description: Define the base uri for relative uri.
| Description: Define loading policy for all resources type in case of a resource type dedicated directive is not defined (fallback).
| Description: Define which scripts the protected resource can execute.
| Description: Define which styles (CSS) the user applies to the protected resource.
| Description: Define from where the protected resource can load images.
| Description: Define from where the protected resource can load video and audio.
| Description: Deprecated and replaced by child-src. Define from where the protected resource can embed frames.
| Description: Define from where the protected resource can be embedded in frames.
| Description: Define from where the protected resource can load fonts.
| Description: Define which URIs the protected resource can load using script interfaces.
| Description: Define which URIs can be used as the action of HTML form elements.
| X_Permitted_Cross_Domain_Policies:
| Header: X-Permitted-Cross-Domain-Policies: none
| Description: No policy files are allowed anywhere on the target server, including this master policy file.
| Cookie:
| Cookies are secured with Secure Flag in HTTPS Connection
| Cache_Control:
|_ Header: Cache-Control: no-cache, no-store, must-revalidate
| http-enum:
|_ /robots.txt: Robots file
|_http-comments-displayer: Couldn't find any comments.
|_http-chrono: Request times for /index.php/login; avg: 2458.85ms; min: 1703.33ms; max: 3689.52ms
|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
|_http-mobileversion-checker: No mobile version detected.
| http-traceroute:
| Status Code
| Hop #1: 404
| Hop #2: 302
| Hop #3: 302
| server
| Hop #1
| Hop #2: Apache/2.4.66 (Debian)
| Hop #3: Apache/2.4.66 (Debian)
| content-type
| Hop #1: text/plain; charset=utf-8
| Hop #2: text/html; charset=UTF-8
| Hop #3: text/html; charset=UTF-8
| content-length
| Hop #1: 19
| Hop #2: 0
| Hop #3: 0
| location
| Hop #1
| Hop #2: https://nextcloud.lan.ddnsgeek.com/index.php/login
|_ Hop #3: https://nextcloud.lan.ddnsgeek.com/index.php/login
| http-php-version: Logo query returned unknown hash 7209a04a90229576f2e4ff38710cbbd5
| Credits query returned unknown hash 7209a04a90229576f2e4ff38710cbbd5
|_Version from header x-powered-by: PHP/8.3.30
| http-sitemap-generator:
| Directory structure:
| /index.php/
| Other: 1
| Longest directory structure:
| Depth: 1
| Dir: /index.php/
| Total files found (by extension):
|_ Other: 1
| http-headers:
| Cache-Control: no-cache, no-store, must-revalidate
| Content-Length: 16047
| Content-Security-Policy: default-src 'none';base-uri 'none';manifest-src 'self';script-src 'nonce-X594h5DgY3hTUT16aMu7aHJx7JGnNKQBMo8qHmmeJz4=';script-src-elem 'strict-dynamic' 'nonce-X594h5DgY3hTUT16aMu7aHJx7JGnNKQBMo8qHmmeJz4=';style-src 'self' 'unsafe-inline';img-src 'self' data: blob: https://*.tile.openstreetmap.org;font-src 'self' data:;connect-src 'self';media-src 'self';frame-src 'self';frame-ancestors 'self';form-action 'self'
| Content-Type: text/html; charset=UTF-8
| Date: Tue, 14 Apr 2026 03:52:32 GMT
| Feature-Policy: autoplay 'self';camera 'none';fullscreen 'self';geolocation 'none';microphone 'none';payment 'none'
| Referrer-Policy: same-origin
| Server: Apache/2.4.66 (Debian)
| Set-Cookie: ocexfs76yoe2=d6e07917a213bb55c27a45dc41105050; path=/; secure; HttpOnly; SameSite=Lax
| Set-Cookie: oc_sessionPassphrase=iqjM5ZelDa7FDYnEagm7YKi4xAYxY%2By8HsYpzip6EAIve%2Fcaq75I8p1eNvhJHnoBu6bc3eJ3eRe2BYmlguMWP2cXiG2GI4pZRqf%2F3ml0UkUEyZZ%2B1Fbc78rWd%2B%2Fr1SzL; path=/; secure; HttpOnly; SameSite=Lax
| Set-Cookie: ocexfs76yoe2=d6e07917a213bb55c27a45dc41105050; path=/; secure; HttpOnly; SameSite=Lax
| Set-Cookie: __Host-nc_sameSiteCookielax=true; path=/; httponly;secure; expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=lax
| Set-Cookie: __Host-nc_sameSiteCookiestrict=true; path=/; httponly;secure; expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=strict
| Set-Cookie: ocexfs76yoe2=d6e07917a213bb55c27a45dc41105050; path=/; secure; HttpOnly; SameSite=Lax
| Set-Cookie: ocexfs76yoe2=d6e07917a213bb55c27a45dc41105050; path=/; secure; HttpOnly; SameSite=Lax
| Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
| X-Content-Type-Options: nosniff
| X-Frame-Options: SAMEORIGIN
| X-Permitted-Cross-Domain-Policies: none
| X-Powered-By: PHP/8.3.30
| X-Request-Id: StUWwRgKsFOpX9ZPeriD
| X-Robots-Tag: noindex, nofollow
| X-Xss-Protection: 1; mode=block
| Connection: close
|
|_ (Request type: HEAD)
| http-title: Login \xE2\x80\x93 Nextcloud
|_Requested resource was https://nextcloud.lan.ddnsgeek.com/index.php/login
|_http-errors: Couldn't find any error pages.
Read data files from: /usr/share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Tue Apr 14 03:57:36 2026 -- 1 IP address (1 host up) scanned in 517.53 seconds