Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Sercurius.net - a handy vulnerability scanner

Sercurius.net - a handy vulnerability scanner

Scheduled Pinned Locked Moved Discuss
securitynginx
6 Posts 3 Posters 1.1k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcusquinnM Offline
      marcusquinnM Offline
      marcusquinn
      wrote on last edited by girish
      #1

      https://sercurius.net

      Although trying to get perfect scores can drive you bonkers, maybe useful for any quick wins.

      Web Design https://www.evergreen.je
      Development https://brandlight.org
      Life https://marcusquinn.com

      1 Reply Last reply
      2
      • ? Offline
        ? Offline
        A Former User
        wrote on last edited by
        #2

        Useful site, Marcus!

        some example results:-
        https://marcusquinn.com/ = Security grade 85%
        https://forum.cloudron.io/ = Security grade 83%
        my Cloudron dashboard = Security grade 85%

        1 Reply Last reply
        1
        • marcusquinnM Offline
          marcusquinnM Offline
          marcusquinn
          wrote on last edited by
          #3

          Thanks! 😄 My site's just a static page (Ulysses > GitLab Pages) for now until I get going with Ghost. I still like the idea of mirroring a static version to my personal GitLab & GitHub Page repos, since theoretically they can live longer than me, or my payment card at least 😂

          Web Design https://www.evergreen.je
          Development https://brandlight.org
          Life https://marcusquinn.com

          1 Reply Last reply
          1
          • girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by
            #4

            Ah, nice link. Thanks @marcuswquinn .

            For our Cloudron dashboard, we got out 79% 😞

            marcusquinnM 1 Reply Last reply
            0
            • girishG Offline
              girishG Offline
              girish
              Staff
              wrote on last edited by girish
              #5

              Investigating:

              • It seems the port scanner is very upset about email ports but hey Cloudron is our mail server.
              • Complaints about nginx server version being shown. I have long resisted this but I bit the bullet and hid the nginx version from the next release - https://git.cloudron.io/cloudron/box/-/commit/b14b5f141bc6a45fde376fc465831424f5218904
              • It complains about port 6000 being open, but it's our git.cloudron.io port. So false positive
              • Complaint about X-Frame-Options is also false positive. That option is now obsolete, we use frame-ancestors none in CSP - https://git.cloudron.io/cloudron/box/-/blob/master/src/nginxconfig.ejs#L100
              • Finally, there is some warning about https://developer.mozilla.org/en-US/docs/Web/HTTP/Feature_Policy which it seems is renamed to Permissions-Policy. Haven't heard of this one before.
              1 Reply Last reply
              3
              • girishG girish

                Ah, nice link. Thanks @marcuswquinn .

                For our Cloudron dashboard, we got out 79% 😞

                marcusquinnM Offline
                marcusquinnM Offline
                marcusquinn
                wrote on last edited by
                #6

                @girish I think all these % numbers are a bit misleading and opinionated - but as you rightly detail it's a case of looking at the appropriateness of each item and reasonability.

                It's impossible to know or remember everything but still a nice too for a quick review to see if there's any easy wins, and I suppose the scoring mechanism could be handy marketing for some once a certain level is considered reasonably hardened.

                Web Design https://www.evergreen.je
                Development https://brandlight.org
                Life https://marcusquinn.com

                1 Reply Last reply
                1
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                  • Login

                  • Don't have an account? Register

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • Bookmarks
                  • Search