246 lines
9.9 KiB
Plaintext
246 lines
9.9 KiB
Plaintext
WhatWeb report for https://nextcloud.lan.ddnsgeek.com:443
|
||
Status : 302 Found
|
||
Title : <None>
|
||
IP : 167.179.167.166
|
||
Country : NEW ZEALAND, NZ
|
||
|
||
Summary : Apache[2.4.66], Cookies[__Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2], HTTPServer[Debian Linux][Apache/2.4.66 (Debian)], HttpOnly[__Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2], PHP[8.3.30], RedirectLocation[https://nextcloud.lan.ddnsgeek.com/index.php/login], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-robots-tag], X-Frame-Options[SAMEORIGIN], X-Powered-By[PHP/8.3.30], X-XSS-Protection[1; mode=block]
|
||
|
||
Detected Plugins:
|
||
[ Apache ]
|
||
The Apache HTTP Server Project is an effort to develop and
|
||
maintain an open-source HTTP server for modern operating
|
||
systems including UNIX and Windows NT. The goal of this
|
||
project is to provide a secure, efficient and extensible
|
||
server that provides HTTP services in sync with the current
|
||
HTTP standards.
|
||
|
||
Version : 2.4.66 (from HTTP Server Header)
|
||
Google Dorks: (3)
|
||
Website : http://httpd.apache.org/
|
||
|
||
[ Cookies ]
|
||
Display the names of cookies in the HTTP headers. The
|
||
values are not returned to save on space.
|
||
|
||
String : ocexfs76yoe2
|
||
String : oc_sessionPassphrase
|
||
String : ocexfs76yoe2
|
||
String : __Host-nc_sameSiteCookielax
|
||
String : __Host-nc_sameSiteCookiestrict
|
||
String : ocexfs76yoe2
|
||
|
||
[ HTTPServer ]
|
||
HTTP server header string. This plugin also attempts to
|
||
identify the operating system from the server header.
|
||
|
||
OS : Debian Linux
|
||
String : Apache/2.4.66 (Debian) (from server string)
|
||
|
||
[ HttpOnly ]
|
||
If the HttpOnly flag is included in the HTTP set-cookie
|
||
response header and the browser supports it then the cookie
|
||
cannot be accessed through client side script - More Info:
|
||
http://en.wikipedia.org/wiki/HTTP_cookie
|
||
|
||
String : __Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2
|
||
|
||
[ PHP ]
|
||
PHP is a widely-used general-purpose scripting language
|
||
that is especially suited for Web development and can be
|
||
embedded into HTML. This plugin identifies PHP errors,
|
||
modules and versions and extracts the local file path and
|
||
username if present.
|
||
|
||
Version : 8.3.30
|
||
Google Dorks: (3)
|
||
Website : http://www.php.net/
|
||
|
||
[ RedirectLocation ]
|
||
HTTP Server string location. used with http-status 301 and
|
||
302
|
||
|
||
String : https://nextcloud.lan.ddnsgeek.com/index.php/login (from location)
|
||
|
||
[ Strict-Transport-Security ]
|
||
Strict-Transport-Security is an HTTP header that restricts
|
||
a web browser from accessing a website without the security
|
||
of the HTTPS protocol.
|
||
|
||
String : max-age=15552000; includeSubDomains; preload
|
||
|
||
[ UncommonHeaders ]
|
||
Uncommon HTTP server headers. The blacklist includes all
|
||
the standard headers and many non standard but common ones.
|
||
Interesting but fairly common headers should have their own
|
||
plugins, eg. x-powered-by, server and x-aspnet-version.
|
||
Info about headers can be found at www.http-stats.com
|
||
|
||
String : content-security-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-robots-tag (from headers)
|
||
|
||
[ X-Frame-Options ]
|
||
This plugin retrieves the X-Frame-Options value from the
|
||
HTTP header. - More Info:
|
||
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
|
||
aspx
|
||
|
||
String : SAMEORIGIN
|
||
|
||
[ X-Powered-By ]
|
||
X-Powered-By HTTP header
|
||
|
||
String : PHP/8.3.30 (from x-powered-by string)
|
||
|
||
[ X-XSS-Protection ]
|
||
This plugin retrieves the X-XSS-Protection value from the
|
||
HTTP header. - More Info:
|
||
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
|
||
aspx
|
||
|
||
String : 1; mode=block
|
||
|
||
HTTP Headers:
|
||
HTTP/1.1 302 Found
|
||
Content-Length: 0
|
||
Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-eJJaUYSl69LnzUT5f2oen13g5dGL7ymBpryYUsbS1rM='; style-src 'self' 'unsafe-inline'; frame-src *; img-src * data: blob:; font-src 'self' data:; media-src *; connect-src *; object-src 'none'; base-uri 'self';
|
||
Content-Type: text/html; charset=UTF-8
|
||
Date: Tue, 14 Apr 2026 03:52:32 GMT
|
||
Location: https://nextcloud.lan.ddnsgeek.com/index.php/login
|
||
Referrer-Policy: no-referrer
|
||
Server: Apache/2.4.66 (Debian)
|
||
Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
|
||
Set-Cookie: oc_sessionPassphrase=5pTvnvYZRBKLnd46XMg0XJgoZATFmwg0xpb9U1MWOfbLENZfrRG142BX4xAg7bm56hCNDQECmNcTK4g1NdWTqtlGZEsFXybcLKF2X9emXfyh%2BvINw27UVedM9bAdvRzR; path=/; secure; HttpOnly; SameSite=Lax
|
||
Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
|
||
Set-Cookie: __Host-nc_sameSiteCookielax=true; path=/; httponly;secure; expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=lax
|
||
Set-Cookie: __Host-nc_sameSiteCookiestrict=true; path=/; httponly;secure; expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=strict
|
||
Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
|
||
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
|
||
X-Content-Type-Options: nosniff
|
||
X-Frame-Options: SAMEORIGIN
|
||
X-Permitted-Cross-Domain-Policies: none
|
||
X-Powered-By: PHP/8.3.30
|
||
X-Robots-Tag: noindex, nofollow
|
||
X-Xss-Protection: 1; mode=block
|
||
Connection: close
|
||
|
||
WhatWeb report for https://nextcloud.lan.ddnsgeek.com/index.php/login
|
||
Status : 200 OK
|
||
Title : ,Login – Nextcloud
|
||
IP : 167.179.167.166
|
||
Country : NEW ZEALAND, NZ
|
||
|
||
Summary : Cookies[ocexfs76yoe2], HTML5, HTTPServer[Debian Linux][Apache/2.4.66 (Debian)], HttpOnly[ocexfs76yoe2], Open-Graph-Protocol[website], PHP[8.3.30], Script, Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,feature-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-request-id,x-robots-tag], X-Frame-Options[SAMEORIGIN], X-Powered-By[PHP/8.3.30], X-XSS-Protection[1; mode=block]
|
||
|
||
Detected Plugins:
|
||
[ Cookies ]
|
||
Display the names of cookies in the HTTP headers. The
|
||
values are not returned to save on space.
|
||
|
||
String : ocexfs76yoe2
|
||
|
||
[ HTML5 ]
|
||
HTML version 5, detected by the doctype declaration
|
||
|
||
|
||
[ HTTPServer ]
|
||
HTTP server header string. This plugin also attempts to
|
||
identify the operating system from the server header.
|
||
|
||
OS : Debian Linux
|
||
String : Apache/2.4.66 (Debian) (from server string)
|
||
|
||
[ HttpOnly ]
|
||
If the HttpOnly flag is included in the HTTP set-cookie
|
||
response header and the browser supports it then the cookie
|
||
cannot be accessed through client side script - More Info:
|
||
http://en.wikipedia.org/wiki/HTTP_cookie
|
||
|
||
String : ocexfs76yoe2
|
||
|
||
[ Open-Graph-Protocol ]
|
||
The Open Graph protocol enables you to integrate your Web
|
||
pages into the social graph. It is currently designed for
|
||
Web pages representing profiles of real-world things .
|
||
things like movies, sports teams, celebrities, and
|
||
restaurants. Including Open Graph tags on your Web page,
|
||
makes your page equivalent to a Facebook Page.
|
||
|
||
Version : website
|
||
|
||
[ PHP ]
|
||
PHP is a widely-used general-purpose scripting language
|
||
that is especially suited for Web development and can be
|
||
embedded into HTML. This plugin identifies PHP errors,
|
||
modules and versions and extracts the local file path and
|
||
username if present.
|
||
|
||
Version : 8.3.30
|
||
Google Dorks: (3)
|
||
Website : http://www.php.net/
|
||
|
||
[ Script ]
|
||
This plugin detects instances of script HTML elements and
|
||
returns the script language/type.
|
||
|
||
|
||
[ Strict-Transport-Security ]
|
||
Strict-Transport-Security is an HTTP header that restricts
|
||
a web browser from accessing a website without the security
|
||
of the HTTPS protocol.
|
||
|
||
String : max-age=15552000; includeSubDomains; preload
|
||
|
||
[ UncommonHeaders ]
|
||
Uncommon HTTP server headers. The blacklist includes all
|
||
the standard headers and many non standard but common ones.
|
||
Interesting but fairly common headers should have their own
|
||
plugins, eg. x-powered-by, server and x-aspnet-version.
|
||
Info about headers can be found at www.http-stats.com
|
||
|
||
String : content-security-policy,feature-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-request-id,x-robots-tag (from headers)
|
||
|
||
[ X-Frame-Options ]
|
||
This plugin retrieves the X-Frame-Options value from the
|
||
HTTP header. - More Info:
|
||
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
|
||
aspx
|
||
|
||
String : SAMEORIGIN
|
||
|
||
[ X-Powered-By ]
|
||
X-Powered-By HTTP header
|
||
|
||
String : PHP/8.3.30 (from x-powered-by string)
|
||
|
||
[ X-XSS-Protection ]
|
||
This plugin retrieves the X-XSS-Protection value from the
|
||
HTTP header. - More Info:
|
||
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
|
||
aspx
|
||
|
||
String : 1; mode=block
|
||
|
||
HTTP Headers:
|
||
HTTP/1.1 200 OK
|
||
Cache-Control: no-cache, no-store, must-revalidate
|
||
Content-Encoding: gzip
|
||
Content-Length: 5801
|
||
Content-Security-Policy: default-src 'none';base-uri 'none';manifest-src 'self';script-src 'nonce-SVXVLb4Re1+OOOXuQ3YRupmmoh1cwSYDPAn4J796nvU=';script-src-elem 'strict-dynamic' 'nonce-SVXVLb4Re1+OOOXuQ3YRupmmoh1cwSYDPAn4J796nvU=';style-src 'self' 'unsafe-inline';img-src 'self' data: blob: https://*.tile.openstreetmap.org;font-src 'self' data:;connect-src 'self';media-src 'self';frame-src 'self';frame-ancestors 'self';form-action 'self'
|
||
Content-Type: text/html; charset=UTF-8
|
||
Date: Tue, 14 Apr 2026 03:53:08 GMT
|
||
Feature-Policy: autoplay 'self';camera 'none';fullscreen 'self';geolocation 'none';microphone 'none';payment 'none'
|
||
Referrer-Policy: same-origin
|
||
Server: Apache/2.4.66 (Debian)
|
||
Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
|
||
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
|
||
X-Content-Type-Options: nosniff
|
||
X-Frame-Options: SAMEORIGIN
|
||
X-Permitted-Cross-Domain-Policies: none
|
||
X-Powered-By: PHP/8.3.30
|
||
X-Request-Id: xJN1PJW80BokVwJXwvnU
|
||
X-Robots-Tag: noindex, nofollow
|
||
X-Xss-Protection: 1; mode=block
|
||
Connection: close
|
||
|
||
|