nextcloud security issue?

January 19, 2023, 15:08

jannik44

found out that a random guy created an account on my cloud and managed it somehow to dump a 60GB file called "all_in_one.7z" into it(the account is limited to 10GB) and that file does not show up in the user table, should i take that serious or is that just a file with manupilated metadata or dmth like that?

lupine3rd

Better hope that's not some poison pill content in there...

lupine3rd

Could be someone who runs the data centers for nextcloud performing an attack which causes nextcloud to spend more than budgeted for virtual storage space.

lupine3rd

Or maybe a nextcloud competitor

lupine3rd

Or maybe the manufacturer of physical hard drives performing the attack

lupine3rd

Or the illuminati

lupine3rd

More likely to just be some kind of porn, tho

lupine3rd

Also

lupine3rd

Don't assume pronouns

lupine3rd

How do you know it was a guy?

lupine3rd

Also, don't assume stochastic nature, either.

lupine3rd

How do you know it was random?

lupine3rd

🙃

lupine3rd

Good thing it wasn't some illegal content in there and was just a joker.

lupine3rd

That'll teach you to play with unknown code outside of a sandbox!

lupine3rd

Don't execute....anything. ever.

lupine3rd

Nothing you didn't write for yourself.

ampueromalo

first, how did he find your nextcloud url? "secure" it with a subdirectory second, why can random people create accounts on your nextcloud instance?

lupine3rd

Since this happened from a "random guy", one can only assume that he got his access randomly.

lupine3rd

In terms of answering your second question... That's because privacy and data security is a joke. Either this was a random cred-stuffing attack leveraging a pw list, or an attack against nextcloud, leveraging a vulnerability in the service, or a direct attack against the OP leveraging a key logger on his system. Or perhaps the OP has his nextcloud configured to accept writes from random dudes.