Repository navigation
Data folder accessible if "Satisfy Any" is set #6449
Description
Activity
Sorry for double post then. At least the malicious setting has been identified here, which is also present on #6281 .
As first fast reaction I think an adjustment of the related admin manual part would be good, as many users seem to use
Satisfy Any, even they don't need it.But of course it would be great, if e.g.
.htaccesscould be modified to block access, even ifSatisfy Anyis set in nextcloud vhost/config. Wouldn'tSatisfy Allin every case inside.htaccessoverwrite it? I will test this later.€: As there is a certain use case (apache folder authentication) for
Satisfy Any, it should be indeed testet if it works in that case as expected without opening the data directory. I have to find out first how to configure this folder authentication 😆 , maybe someone is faster.cc @nextcloud/security
Just played around a bit:
- My webserver root is
/var/www/and nextcloud root is/var/www/nextcloud/. - I adjusted my apache2.conf to add folder authentication to the webserver root and created a password for this by
htpasswd -c /mnt/sda/apachepasswords root:
<Directory /var/www/> DirectoryIndex index.php index.html Options Indexes FollowSymLinks AllowOverride None #Require all granted //need to be commented out, because it destroys the following authentication attempt :) #folder authentication start AuthType Basic AuthName "Restricted Files" AuthBasicProvider file AuthUserFile /mnt/sda/apachepasswords Require user root #folder authentication end </Directory>- After apache restart nextcloud web access, desktop clients and carddav + caldav asked for authentication/user passwords, as is was expected.
- Now I added
Satisfy Anytonextcloud.confand access to nextcloud worked well again, BUT also direct access to my data worked well, as described above. - I now adjusted the .htaccess by adding
Satisfy Allto the Apache 2.4 part:
# Generated by Nextcloud on 2017-06-02 11:21:34 # line below if for Apache 2.4 <ifModule mod_authz_core.c> Require all denied Satisfy All </ifModule> # line below if for Apache 2.2 <ifModule !mod_authz_core.c> deny from all Satisfy All </ifModule> # section for Apache 2.2 and 2.4 <ifModule mod_autoindex.c> IndexIgnore * </ifModule>- ...and indeed access to data folder got denied again. But by the way nextcloud web ui/folder app etc. worked well, so no full block to the data or something 😉.
So as conclusion:
Require all granted/deniedandSatisfy Any/Allseem to work independently beside each other, granting/denying access. If each one of these directives is set to allow access to the parent folder/globally, each need to be overwritten in the subdirectory to definitely block access.So as far as I could test it, fix would be to adjust /data/.htaccess to meet the example above and keep the
Satisfy Anyhint in admin manual, but explain it a bid more to make clear, that people should NOT add it, in case they do not know exactly that they need it and what they are doing.- My webserver root is
- changed the title
[-][SECURITY] Data folder accessible if "Satisfy Any" is set[/-][+]Data folder accessible if "Satisfy Any" is set[/+]on Sep 12, 2017 Any news about this? I still see here and there users with this settings, that definitely don't need it and might expose their data with it. @
- addedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Jun 20, 2018 I upgraded from 13.0.6.1 to 14.0.0 and suddenly NC warned me that .htaccess didn't work and my data would be exposed which indeed it was. Removing
Satisfy Anyfrom the apache virt. host file fixed it as well.
Before the upgrade this wasn't an issue. Regression?- removedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Sep 11, 2018 I see the same: When I upgrade nextcloud, it replaces my .htaccess file in the data folder with the following:
# line below if for Apache 2.4 <ifModule mod_authz_core.c> Require all denied </ifModule> # line below if for Apache 2.2 <ifModule !mod_authz_core.c> deny from all Satisfy All </ifModule> # section for Apache 2.2 and 2.4 <ifModule mod_autoindex.c> IndexIgnore * </ifModule>However, this makes the data folder world readable, probably because of some setting in apache that I did in order for caldav/carddav to work (using the guide).
- I would expect that nextcloud would make a very clear warning about this, much more than the red flag in the admin panel.
The .htaccess file that works for me is the following:
#<ifModule mod_authz_core.c> Require all denied #</ifModule> # line below if for Apache 2.2 #<ifModule !mod_authz_core.c> deny from all Satisfy All #</ifModule> # section for Apache 2.2 and 2.4 <ifModule mod_autoindex.c> IndexIgnore * </ifModule>i.e. with the if statements commented out.
System:
# cat /etc/lsb-release DISTRIB_ID=Ubuntu DISTRIB_RELEASE=18.04 DISTRIB_CODENAME=bionic DISTRIB_DESCRIPTION="Ubuntu 18.04.1 LTS" # php --version PHP 7.2.10-0ubuntu0.18.04.1 (cli) (built: Sep 13 2018 13:45:02) ( NTS ) Copyright (c) 1997-2018 The PHP Group Zend Engine v3.2.0, Copyright (c) 1998-2018 Zend Technologies with Zend OPcache v7.2.10-0ubuntu0.18.04.1, Copyright (c) 1999-2018, by Zend Technologies # a2query -m authn_core (enabled by maintainer script) auth_basic (enabled by maintainer script) deflate (enabled by maintainer script) setenvif (enabled by maintainer script) alias (enabled by maintainer script) rewrite (enabled by site administrator) mpm_prefork (enabled by site administrator) authz_user (enabled by maintainer script) ssl (enabled by site administrator) proxy (enabled by site administrator) socache_shmcb (enabled by site administrator) proxy_http (enabled by site administrator) negotiation (enabled by maintainer script) php7.2 (enabled by site administrator) access_compat (enabled by maintainer script) filter (enabled by maintainer script) autoindex (enabled by maintainer script) reqtimeout (enabled by maintainer script) dir (enabled by maintainer script) authz_core (enabled by maintainer script) env (enabled by maintainer script) headers (enabled by site administrator) status (enabled by maintainer script) authn_file (enabled by maintainer script) mime (enabled by maintainer script) authz_host (enabled by maintainer script)I have my installation at
/var/www/html/mycustomname/and as per https://docs.nextcloud.com/server/13/admin_manual/installation/source_installation.html#ubuntu-installation-label I have "Satisfy Any" in my site config.The main problem is that I had this security issue solved, but the upgrade just threw me back, and I only noticed it by chance.
I happened yesterday when I upgraded to 14.0.3.Reacted by MichaIng and fernandoc2021#<ifModule mod_authz_core.c> Require all denied #</ifModule> # line below if for Apache 2.2 #<ifModule !mod_authz_core.c> deny from all Satisfy All #</ifModule>Strange, this is not 100% the same. The
.htaccessat first looks quite reasonable to me:- In case
mod_authz_coreis available, use the access permission directive it brings. - If it is not available, use the old fashioned way to restrict access.
However, it seems that
Require all denieddoes not overrideSatisfy Any, whileSatisfy Alldoes.Require alldirective is brought bymod_authz_core, which is only available since Apache2.4, so the ifModule statement make sense here: https://httpd.apache.org/docs/2.4/mod/mod_authz_core.htmldeny from allis more complicated. To simply assume it is always available ifmod_authz_coreis not, is of course wrong, also to assume it is only required, ifmod_authz_coreis not available, is even more wrong. For my impression it should be simply always set, if the directive is available.- The problem is on 2.4 it's marked as deprecated and only available via mod_access_compat.
- But on 2.2 it's available via mod_authz_host, which also exist on 2.4 but provides new fashioned directives there.
- So not sure how to do this best, but for my impression
deny from allshould be always set, if thedenydirective is available, regardless ofRequire all, since we cannot be sure it's overridden.
Satisfy Allshould be as well always set, to override any otherSatisfy(most importantlySatisfy Any) directives, possibly set in Apache confs.- On 2.2 it is a core directive: https://httpd.apache.org/docs/2.2/de/mod/core.html#satisfy
- On 2.4 it's again part of
mod_access_compat: https://httpd.apache.org/docs/2.4/mod/mod_access_compat.html#satisfy
What definitely need to be changed:
- Remove
Satisfy Anyfrom any example setup in documentation. Instead change the section with a clear warning, that this directive should never be added. This should be addressed to the docs repo then. - Add
deny from allandSatisfy Alldirectives todata/.htaccesswhenever they are available, to override other values set, which seem to not be overridden byRequire. Although it would need somehow an Apache version check.- Further research: https://stackoverflow.com/questions/10707186/detect-apache-version-in-apache-config
- So it seems not natively possible to check for Apache version inside config files.
- But via nested module checks, a similar result can be achieved, which guarantees max security without any compatibility issues:
# line below if for Apache 2.4 <ifModule mod_authz_core.c> Require all denied </ifModule> <ifModule mod_access_compat.c> deny from all Satisfy All </ifModule> # line below if for Apache 2.2 <ifModule !mod_authz_core.c> <ifModule !mod_access_compat.c> <ifModule mod_authz_host.c> deny from all </ifModule> Satisfy All </ifModule> </ifModule>- Last issue I see is, if on Apache 2.4
mod_authz_core+mod_access_compatis disabled, butmod_authz_hostenabled. I didn't (yet) test, but I think it's impossible, sincemod_authz_hostshould depend onmod_authz_core(EDIT: It does!).
Reacted by mgartinReacted by fernandoc2021- In case
@MichaIng what is the status here?
I'm not too well with mod_authz and such, but is your last post a working solution? If so, do you think it should be nice to have it on the docs? :)- added0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmap
on Aug 15, 2019 17 remaining items
First of all there are some issues with your configs:
Move the following into the the 443 vhost. I wonder if you were every able to connect via HTTPS currently?SSLEngine on SSLCertificateFile /root/cloudflare/domain.yt.pem SSLCertificateKeyFile /root/cloudflare/domain.yt.keyRemove the following, doesn't and probably didn't ever had any effect and has been removed from the Nextcloud docs as well in the meantime: nextcloud/documentation#1800
SetEnv HOME /var/www/cloud.domain.yt SetEnv HTTP_HOME /var/www/cloud.domain.ytAnd since you do not actually use different vhosts with different names, it makes sense to move
ServerName cloud.domain.ytinto the parent server configuration as global server name (and remove it hence from both vhosts),ServerAlias cloud.domain.ytcan be removed andServerAdmin [email protected]as well if you do not set it to a real email address that you want to share with visitors.But that alone doesn't explain that your data can be accessed directly. Where is it located? Just in
/var/www/cloud.domain.yt/data?Which OS and Apache version do you use (
apachectl -v)?Is there a
AccessFileName .htaccessdirective in/etc/apache2/apache2.confor another included config file?Hello,
AccessFileName .htaccess is existing in the config.
I use Ubuntu 21.10 and Apache/2.4.48 (Ubuntu)
And yes its located in /var/www/cloud.domain.yt/data
And this URL works in browser access works/does not redirect you to the login/default page?
https://cloud.domain.yt/data/index.htmlor
http://cloud.domain.yt/data/index.htmlNope it just shows a blank page
Strange, so it is accessible while
/var/www/cloud.domain.yt/data/.htaccessshould prevent it, leading to a 403 which redirects you to the entry page.You need to go though all loaded Apache2 configurations, there must be something which block Apache2 from using it. E.g. to check for all cases of the
AccessFileNamedirective:grep -r 'AccessFileName' /etc/apache2And to check for read permissions of that file:
ls -l /var/www/cloud.domain.yt/data/.htaccess
And to check for Apache2 error messages:
journalctl -u apache2 cat /var/log/apache2/error.log
root@v3179:~# grep -r 'AccessFileName' /etc/apache2
/etc/apache2/apache2.conf:# AccessFileName: The name of the file to look for in each directory
/etc/apache2/apache2.conf:AccessFileName .htaccess-rw-r--r-- 1 www-data www-data 542 Nov 8 19:38 /var/www/cloud.domain.yt/data/.htaccess
journalctl and cat: https://paste.deko.yt/view/d5add159
[so:warn] [pid 520557] AH01574: module heade>
Can you show the whole line of this log?
Looks like the
richdocumentscodeapp requires an update or different configuration according to the logs it produces. However, I don't see something which would.htaccessfrom being used. You could try to add some random invalid line to/var/www/cloud.domain.yt/data/.htaccess, then accesshttp://cloud.domain.yt/data/index.htmland check back whether this produces any error in/var/log/apache2/error.log, just to verify that it is indeed not parsed at all.When I add random invalid lines, this error comes in data/index.html
Internal Server Error
The server encountered an internal error or misconfiguration and was unable to complete your request.Please contact the server administrator at [email protected] to inform them of the time this error occurred, and the actions you performed just before this error.
More information about this error may be available in the server error log.
Apache/2.4.48 (Ubuntu) Server at cloud.domain.yt Port 80
No new errors in the error.log https://paste.deko.yt/view/9589e71a
Also something I recognized. Since some days, nextcloud also says phpimagick is missing, but its literally installed and enabled. It just came from one to the other night.
php-imagickcannot be related to this, it is not required an whether being a good recommendation at all or not still matter of discussion: #13099So the
.htaccessfile is read. Last idea I have is that the related Apache2 module is not enabled, but that's actually hard to achieve (at least on Debian/Ubuntu variants you get an interactive warning). Try that:a2enmod authz_core
root@v3179:
# a2enmod authz_core#
Module authz_core already enabled
root@v3179:Okay, then I'm basically out of ideas. The config file is parsed and this module is enabled, then access should be blocked:
<IfModule mod_authz_core.c> Require all denied </IfModule>Even if
Satisfy Anyis set, with your Apache2 version this would mean thatmod_access_compatis enabled which would in turn overrideSatisfy Anyas a result of this very issue and fix:<IfModule mod_access_compat.c> Order Allow,Deny Deny from all Satisfy All </IfModule>While it would be interesting to have this debugged, probably on a more specialised Apache or webserver forum, StackExchange or so where more experts are attracted, an alternative for you now would be to move your Nextcloud userdata to a different location outside of the webroot: https://help.nextcloud.com/t/howto-change-move-data-directory-after-installation/17170
(Older HowTo, but I keep it updated)I just hope a Nextcloud Dev sees my problem and can help me here. If not, I probably need to find an alternative to nextcloud (tho I cant really find one except owncloud)
Likely not on a closed issue which has been addressed already. And furthermore it's not a Nextcloud issue but one with the webserver or its configuration.
So I can do pretty much nothing else then have this security issue? Because I already did everything, that should make the .htaccess file working.
At least I am out of ideas, as long as you leave the data directory inside the webroot. Moving it away is to too hard, following the linked HowTo, and solves all related security issues most reliable. And else, as said, at best you ask for help on a more specialised forum related to webservers and/or Apache2 in particular.
Rewards are always welcome thou, but it is not me that fell above this: https://help.nextcloud.com/t/htaccess-warning-while-configuration-should-be-ok/20280/17?u=michaing
Steps to reproduce
.htaccessfiles are used as expected to prevent access to data folder.Satisfy Anyto nextcloud vhost/config file as mentioned in admin manual as necessary in some cases: https://docs.nextcloud.com/server/12/admin_manual/installation/source_installation.html#additional-apache-configurationsExpected behaviour
Access should be forbidden.
Actual behaviour
Access works very well.
/data/index.htmlis still possible.Server configuration
Operating system: Raspbian/Debian Stretch
Web server: Apache/2.4.25
Database: MariaDB 10.1
PHP version: 7.0.19-1
Nextcloud version: 12.0.2
Updated from an older Nextcloud/ownCloud or fresh install: updated
Where did you install Nextcloud from: downloads.nextcloud.com
Signing status:
Signing status
List of activated apps:
App list
Nextcloud configuration:
Config report
Are you using external storage, if yes which one: no
Are you using encryption: no
Are you using an external user-backend, if yes which one: no
Client configuration
Browser: Opera 49 + Edge 40.15 were tested.
Operating system:
Logs
Web server error log
none
Nextcloud log (data/nextcloud.log)
none
Browser log
nene