Files
autorecon/results/nextcloud.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_whatweb.txt
T
2026-04-14 17:49:38 +10:00

246 lines
9.9 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
WhatWeb report for https://nextcloud.lan.ddnsgeek.com:443
Status : 302 Found
Title : <None>
IP : 167.179.167.166
Country : NEW ZEALAND, NZ
Summary : Apache[2.4.66], Cookies[__Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2], HTTPServer[Debian Linux][Apache/2.4.66 (Debian)], HttpOnly[__Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2], PHP[8.3.30], RedirectLocation[https://nextcloud.lan.ddnsgeek.com/index.php/login], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-robots-tag], X-Frame-Options[SAMEORIGIN], X-Powered-By[PHP/8.3.30], X-XSS-Protection[1; mode=block]
Detected Plugins:
[ Apache ]
The Apache HTTP Server Project is an effort to develop and
maintain an open-source HTTP server for modern operating
systems including UNIX and Windows NT. The goal of this
project is to provide a secure, efficient and extensible
server that provides HTTP services in sync with the current
HTTP standards.
Version : 2.4.66 (from HTTP Server Header)
Google Dorks: (3)
Website : http://httpd.apache.org/
[ Cookies ]
Display the names of cookies in the HTTP headers. The
values are not returned to save on space.
String : ocexfs76yoe2
String : oc_sessionPassphrase
String : ocexfs76yoe2
String : __Host-nc_sameSiteCookielax
String : __Host-nc_sameSiteCookiestrict
String : ocexfs76yoe2
[ HTTPServer ]
HTTP server header string. This plugin also attempts to
identify the operating system from the server header.
OS : Debian Linux
String : Apache/2.4.66 (Debian) (from server string)
[ HttpOnly ]
If the HttpOnly flag is included in the HTTP set-cookie
response header and the browser supports it then the cookie
cannot be accessed through client side script - More Info:
http://en.wikipedia.org/wiki/HTTP_cookie
String : __Host-nc_sameSiteCookielax,__Host-nc_sameSiteCookiestrict,oc_sessionPassphrase,ocexfs76yoe2
[ PHP ]
PHP is a widely-used general-purpose scripting language
that is especially suited for Web development and can be
embedded into HTML. This plugin identifies PHP errors,
modules and versions and extracts the local file path and
username if present.
Version : 8.3.30
Google Dorks: (3)
Website : http://www.php.net/
[ RedirectLocation ]
HTTP Server string location. used with http-status 301 and
302
String : https://nextcloud.lan.ddnsgeek.com/index.php/login (from location)
[ Strict-Transport-Security ]
Strict-Transport-Security is an HTTP header that restricts
a web browser from accessing a website without the security
of the HTTPS protocol.
String : max-age=15552000; includeSubDomains; preload
[ UncommonHeaders ]
Uncommon HTTP server headers. The blacklist includes all
the standard headers and many non standard but common ones.
Interesting but fairly common headers should have their own
plugins, eg. x-powered-by, server and x-aspnet-version.
Info about headers can be found at www.http-stats.com
String : content-security-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-robots-tag (from headers)
[ X-Frame-Options ]
This plugin retrieves the X-Frame-Options value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : SAMEORIGIN
[ X-Powered-By ]
X-Powered-By HTTP header
String : PHP/8.3.30 (from x-powered-by string)
[ X-XSS-Protection ]
This plugin retrieves the X-XSS-Protection value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : 1; mode=block
HTTP Headers:
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-eJJaUYSl69LnzUT5f2oen13g5dGL7ymBpryYUsbS1rM='; style-src 'self' 'unsafe-inline'; frame-src *; img-src * data: blob:; font-src 'self' data:; media-src *; connect-src *; object-src 'none'; base-uri 'self';
Content-Type: text/html; charset=UTF-8
Date: Tue, 14 Apr 2026 03:52:32 GMT
Location: https://nextcloud.lan.ddnsgeek.com/index.php/login
Referrer-Policy: no-referrer
Server: Apache/2.4.66 (Debian)
Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
Set-Cookie: oc_sessionPassphrase=5pTvnvYZRBKLnd46XMg0XJgoZATFmwg0xpb9U1MWOfbLENZfrRG142BX4xAg7bm56hCNDQECmNcTK4g1NdWTqtlGZEsFXybcLKF2X9emXfyh%2BvINw27UVedM9bAdvRzR; path=/; secure; HttpOnly; SameSite=Lax
Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
Set-Cookie: __Host-nc_sameSiteCookielax=true; path=/; httponly;secure; expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=lax
Set-Cookie: __Host-nc_sameSiteCookiestrict=true; path=/; httponly;secure; expires=Fri, 31-Dec-2100 23:59:59 GMT; SameSite=strict
Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Powered-By: PHP/8.3.30
X-Robots-Tag: noindex, nofollow
X-Xss-Protection: 1; mode=block
Connection: close
WhatWeb report for https://nextcloud.lan.ddnsgeek.com/index.php/login
Status : 200 OK
Title : ,Login Nextcloud
IP : 167.179.167.166
Country : NEW ZEALAND, NZ
Summary : Cookies[ocexfs76yoe2], HTML5, HTTPServer[Debian Linux][Apache/2.4.66 (Debian)], HttpOnly[ocexfs76yoe2], Open-Graph-Protocol[website], PHP[8.3.30], Script, Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,feature-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-request-id,x-robots-tag], X-Frame-Options[SAMEORIGIN], X-Powered-By[PHP/8.3.30], X-XSS-Protection[1; mode=block]
Detected Plugins:
[ Cookies ]
Display the names of cookies in the HTTP headers. The
values are not returned to save on space.
String : ocexfs76yoe2
[ HTML5 ]
HTML version 5, detected by the doctype declaration
[ HTTPServer ]
HTTP server header string. This plugin also attempts to
identify the operating system from the server header.
OS : Debian Linux
String : Apache/2.4.66 (Debian) (from server string)
[ HttpOnly ]
If the HttpOnly flag is included in the HTTP set-cookie
response header and the browser supports it then the cookie
cannot be accessed through client side script - More Info:
http://en.wikipedia.org/wiki/HTTP_cookie
String : ocexfs76yoe2
[ Open-Graph-Protocol ]
The Open Graph protocol enables you to integrate your Web
pages into the social graph. It is currently designed for
Web pages representing profiles of real-world things .
things like movies, sports teams, celebrities, and
restaurants. Including Open Graph tags on your Web page,
makes your page equivalent to a Facebook Page.
Version : website
[ PHP ]
PHP is a widely-used general-purpose scripting language
that is especially suited for Web development and can be
embedded into HTML. This plugin identifies PHP errors,
modules and versions and extracts the local file path and
username if present.
Version : 8.3.30
Google Dorks: (3)
Website : http://www.php.net/
[ Script ]
This plugin detects instances of script HTML elements and
returns the script language/type.
[ Strict-Transport-Security ]
Strict-Transport-Security is an HTTP header that restricts
a web browser from accessing a website without the security
of the HTTPS protocol.
String : max-age=15552000; includeSubDomains; preload
[ UncommonHeaders ]
Uncommon HTTP server headers. The blacklist includes all
the standard headers and many non standard but common ones.
Interesting but fairly common headers should have their own
plugins, eg. x-powered-by, server and x-aspnet-version.
Info about headers can be found at www.http-stats.com
String : content-security-policy,feature-policy,referrer-policy,x-content-type-options,x-permitted-cross-domain-policies,x-request-id,x-robots-tag (from headers)
[ X-Frame-Options ]
This plugin retrieves the X-Frame-Options value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : SAMEORIGIN
[ X-Powered-By ]
X-Powered-By HTTP header
String : PHP/8.3.30 (from x-powered-by string)
[ X-XSS-Protection ]
This plugin retrieves the X-XSS-Protection value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : 1; mode=block
HTTP Headers:
HTTP/1.1 200 OK
Cache-Control: no-cache, no-store, must-revalidate
Content-Encoding: gzip
Content-Length: 5801
Content-Security-Policy: default-src 'none';base-uri 'none';manifest-src 'self';script-src 'nonce-SVXVLb4Re1+OOOXuQ3YRupmmoh1cwSYDPAn4J796nvU=';script-src-elem 'strict-dynamic' 'nonce-SVXVLb4Re1+OOOXuQ3YRupmmoh1cwSYDPAn4J796nvU=';style-src 'self' 'unsafe-inline';img-src 'self' data: blob: https://*.tile.openstreetmap.org;font-src 'self' data:;connect-src 'self';media-src 'self';frame-src 'self';frame-ancestors 'self';form-action 'self'
Content-Type: text/html; charset=UTF-8
Date: Tue, 14 Apr 2026 03:53:08 GMT
Feature-Policy: autoplay 'self';camera 'none';fullscreen 'self';geolocation 'none';microphone 'none';payment 'none'
Referrer-Policy: same-origin
Server: Apache/2.4.66 (Debian)
Set-Cookie: ocexfs76yoe2=6bc4aff492fef3b2af03c81e29e9a0e3; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Powered-By: PHP/8.3.30
X-Request-Id: xJN1PJW80BokVwJXwvnU
X-Robots-Tag: noindex, nofollow
X-Xss-Protection: 1; mode=block
Connection: close