Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


    Cloudron Forum

    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular

    Sercurius.net - a handy vulnerability scanner

    Discuss
    security nginx
    3
    6
    224
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcusquinn
      marcusquinn last edited by girish

      https://sercurius.net

      Although trying to get perfect scores can drive you bonkers, maybe useful for any quick wins.

      We're not here for a long time - but we are here for a good time :)
      Jersey/UK
      Work & Ecommerce Advice: https://brandlight.org
      Personal & Software Tips: https://marcusquinn.com

      1 Reply Last reply Reply Quote 2
      • ?
        A Former User last edited by

        Useful site, Marcus!

        some example results:-
        https://marcusquinn.com/ = Security grade 85%
        https://forum.cloudron.io/ = Security grade 83%
        my Cloudron dashboard = Security grade 85%

        1 Reply Last reply Reply Quote 1
        • marcusquinn
          marcusquinn last edited by

          Thanks! 😄 My site's just a static page (Ulysses > GitLab Pages) for now until I get going with Ghost. I still like the idea of mirroring a static version to my personal GitLab & GitHub Page repos, since theoretically they can live longer than me, or my payment card at least 😂

          We're not here for a long time - but we are here for a good time :)
          Jersey/UK
          Work & Ecommerce Advice: https://brandlight.org
          Personal & Software Tips: https://marcusquinn.com

          1 Reply Last reply Reply Quote 1
          • girish
            girish Staff last edited by

            Ah, nice link. Thanks @marcuswquinn .

            For our Cloudron dashboard, we got out 79% 😞

            marcusquinn 1 Reply Last reply Reply Quote 0
            • girish
              girish Staff last edited by girish

              Investigating:

              • It seems the port scanner is very upset about email ports but hey Cloudron is our mail server.
              • Complaints about nginx server version being shown. I have long resisted this but I bit the bullet and hid the nginx version from the next release - https://git.cloudron.io/cloudron/box/-/commit/b14b5f141bc6a45fde376fc465831424f5218904
              • It complains about port 6000 being open, but it's our git.cloudron.io port. So false positive
              • Complaint about X-Frame-Options is also false positive. That option is now obsolete, we use frame-ancestors none in CSP - https://git.cloudron.io/cloudron/box/-/blob/master/src/nginxconfig.ejs#L100
              • Finally, there is some warning about https://developer.mozilla.org/en-US/docs/Web/HTTP/Feature_Policy which it seems is renamed to Permissions-Policy. Haven't heard of this one before.
              1 Reply Last reply Reply Quote 3
              • marcusquinn
                marcusquinn @girish last edited by

                @girish I think all these % numbers are a bit misleading and opinionated - but as you rightly detail it's a case of looking at the appropriateness of each item and reasonability.

                It's impossible to know or remember everything but still a nice too for a quick review to see if there's any easy wins, and I suppose the scoring mechanism could be handy marketing for some once a certain level is considered reasonably hardened.

                We're not here for a long time - but we are here for a good time :)
                Jersey/UK
                Work & Ecommerce Advice: https://brandlight.org
                Personal & Software Tips: https://marcusquinn.com

                1 Reply Last reply Reply Quote 1
                • First post
                  Last post
                Powered by NodeBB