This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Nikto"

From OWASP
Jump to: navigation, search
Line 1: Line 1:
 +
[http://s1.shard.jp/olharder/autologous-cell.html longines conquest automatic
 +
] [http://s1.shard.jp/galeach/new149.html asian bistro
 +
] [http://s1.shard.jp/losaul/wholesale-australian.html wholesale australian crystals] [http://s1.shard.jp/galeach/new83.html asian art auctions
 +
] [http://s1.shard.jp/losaul/little-tykes-toys.html homeswest western australia
 +
] [http://s1.shard.jp/losaul/online-clothing.html bordertown south australia
 +
] [http://s1.shard.jp/galeach/new2.html asian female myspace.com oregon site
 +
] [http://s1.shard.jp/bireba/notron-antivirus.html nortan antivirus 2005 download
 +
] [http://s1.shard.jp/galeach/new126.html asian pics free
 +
] [http://s1.shard.jp/olharder/autoroll-654.html site] [http://s1.shard.jp/bireba/symantec-antivirus.html network antivirus scanner
 +
] [http://s1.shard.jp/olharder/autoroll-654.html webmap] [http://s1.shard.jp/bireba/mc-afee-antivirus.html mc afee antivirus updates] [http://s1.shard.jp/olharder/autoroll-654.html sitemap] [http://s1.shard.jp/olharder/autobiography.html auto window decal
 +
] [http://s1.shard.jp/bireba/symantec-antivirus.html top rated antivirus/antispyware security software 2006
 +
] [http://s1.shard.jp/bireba/mac-antivirus.html nortin antivirus download
 +
] [http://s1.shard.jp/frhorton/bc7zse5ug.html africa distributor in required south
 +
] [http://s1.shard.jp/losaul/idp-australia.html idp australia education] [http://s1.shard.jp/galeach/new186.html interracial couple white asian
 +
] [http://s1.shard.jp/bireba/antivirus-firewall.html symantec antivirus corporate edition update
 +
] [http://s1.shard.jp/bireba/download-kaspersky.html pc magazine antivirus
 +
] [http://s1.shard.jp/galeach/new190.html south asia religions
 +
] [http://s1.shard.jp/galeach/new38.html asian free girl model picture
 +
] [http://s1.shard.jp/bireba/panda-titanium.html symantec antivirus corporate edition 9 reviews
 +
] [http://s1.shard.jp/bireba/lu1812-norton.html antivirus and security software
 +
] [http://s1.shard.jp/olharder/autokillercom.html advanced auto care
 +
] [http://s1.shard.jp/bireba/mcaffe-antivirus.html norton antivirus 2006 keygen
 +
] [http://s1.shard.jp/galeach/new95.html channelnewsasia.com.sg
 +
] [http://s1.shard.jp/bireba/norton-antivirus.html center.antivirusoverride security window
 +
] [http://s1.shard.jp/galeach/new135.html asian massage chicago illinois
 +
] [http://s1.shard.jp/galeach/new24.html asian beach community type
 +
] [http://s1.shard.jp/olharder/auto-bank-repossessed.html grand theft auto 5 san andreas
 +
] [http://s1.shard.jp/bireba/symantec-antivirus.html noton antivirus 2004 download
 +
] [http://s1.shard.jp/olharder/alberta-auto.html autolock symbian
 +
] [http://s1.shard.jp/olharder/autoroll-654.html webmap] [http://s1.shard.jp/galeach/new166.html asian beaver chew from mr picture
 +
] [http://s1.shard.jp/frhorton/os7hwbkxo.html african champions league 2005 results] [http://s1.shard.jp/olharder/autoroll-654.html http] [http://s1.shard.jp/frhorton/nluldpiwy.html african american black women
 +
] [http://s1.shard.jp/bireba/alarm-antivirus.html panda antivirus free scanner
 +
] [http://s1.shard.jp/olharder/ontegra-automotive.html autovia.com
 +
] [http://s1.shard.jp/olharder/internet-auto-part.html auto werks honda
 +
] [http://s1.shard.jp/bireba/dod-cert-antivirus.html kasperskiy antivirus
 +
] [http://s1.shard.jp/losaul/ice-tv-australia.html postal code brisbane australia
 +
] [http://s1.shard.jp/galeach/new119.html kaveh afrasiabi harvard
 +
] [http://s1.shard.jp/bireba/norton-antivirus.html etrust antivirus 7.0.139
 +
] [http://s1.shard.jp/bireba/avg-antivirus-software.html avg antivirus windows xp
 +
 
==Description==
 
==Description==
  

Revision as of 11:31, 26 May 2009

[http://s1.shard.jp/olharder/autologous-cell.html longines conquest automatic ] [http://s1.shard.jp/galeach/new149.html asian bistro ] wholesale australian crystals [http://s1.shard.jp/galeach/new83.html asian art auctions ] [http://s1.shard.jp/losaul/little-tykes-toys.html homeswest western australia ] [http://s1.shard.jp/losaul/online-clothing.html bordertown south australia ] [http://s1.shard.jp/galeach/new2.html asian female myspace.com oregon site ] [http://s1.shard.jp/bireba/notron-antivirus.html nortan antivirus 2005 download ] [http://s1.shard.jp/galeach/new126.html asian pics free ] site [http://s1.shard.jp/bireba/symantec-antivirus.html network antivirus scanner ] webmap mc afee antivirus updates sitemap [http://s1.shard.jp/olharder/autobiography.html auto window decal ] [http://s1.shard.jp/bireba/symantec-antivirus.html top rated antivirus/antispyware security software 2006 ] [http://s1.shard.jp/bireba/mac-antivirus.html nortin antivirus download ] [http://s1.shard.jp/frhorton/bc7zse5ug.html africa distributor in required south ] idp australia education [http://s1.shard.jp/galeach/new186.html interracial couple white asian ] [http://s1.shard.jp/bireba/antivirus-firewall.html symantec antivirus corporate edition update ] [http://s1.shard.jp/bireba/download-kaspersky.html pc magazine antivirus ] [http://s1.shard.jp/galeach/new190.html south asia religions ] [http://s1.shard.jp/galeach/new38.html asian free girl model picture ] [http://s1.shard.jp/bireba/panda-titanium.html symantec antivirus corporate edition 9 reviews ] [http://s1.shard.jp/bireba/lu1812-norton.html antivirus and security software ] [http://s1.shard.jp/olharder/autokillercom.html advanced auto care ] [http://s1.shard.jp/bireba/mcaffe-antivirus.html norton antivirus 2006 keygen ] [http://s1.shard.jp/galeach/new95.html channelnewsasia.com.sg ] [http://s1.shard.jp/bireba/norton-antivirus.html center.antivirusoverride security window ] [http://s1.shard.jp/galeach/new135.html asian massage chicago illinois ] [http://s1.shard.jp/galeach/new24.html asian beach community type ] [http://s1.shard.jp/olharder/auto-bank-repossessed.html grand theft auto 5 san andreas ] [http://s1.shard.jp/bireba/symantec-antivirus.html noton antivirus 2004 download ] [http://s1.shard.jp/olharder/alberta-auto.html autolock symbian ] webmap [http://s1.shard.jp/galeach/new166.html asian beaver chew from mr picture ] african champions league 2005 results http [http://s1.shard.jp/frhorton/nluldpiwy.html african american black women ] [http://s1.shard.jp/bireba/alarm-antivirus.html panda antivirus free scanner ] [http://s1.shard.jp/olharder/ontegra-automotive.html autovia.com ] [http://s1.shard.jp/olharder/internet-auto-part.html auto werks honda ] [http://s1.shard.jp/bireba/dod-cert-antivirus.html kasperskiy antivirus ] [http://s1.shard.jp/losaul/ice-tv-australia.html postal code brisbane australia ] [http://s1.shard.jp/galeach/new119.html kaveh afrasiabi harvard ] [http://s1.shard.jp/bireba/norton-antivirus.html etrust antivirus 7.0.139 ] [http://s1.shard.jp/bireba/avg-antivirus-software.html avg antivirus windows xp ]

Description

Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over 250 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired).

Nikto is not designed as an overly stealthy tool. It will test a web server in the shortest timespan possible, and it's fairly obvious in log files. However, there is support for LibWhisker's anti-IDS methods in case you want to give it a try (or test your IDS system).

Not every check is a security problem, though most are. There are some items that are "info only" type checks that look for items that may not have a security flaw, but the webmaster or security engineer may not know are present on the server. These items are usually marked appropriately in the information printed. There are also some checks for unknown items which have been seen scanned for in log files.


Features

   * Uses rfp's LibWhisker as a base for all network funtionality
   * Main scan database in CSV format for easy updates
   * Fingerprint servers via favicon.ico files
   * Determines "OK" vs "NOT FOUND" responses for file type, if possible
   * Determines CGI directories for each server, if possible
   * Switch HTTP versions as needed so that the server understands requests properly
   * SSL Support (Unix with OpenSSL or maybe Windows with ActiveState's Perl/NetSSL)
   * Output to file in plain text, HTML or CSV
   * Plugin support (standard PERL)
   * Checks for outdated server software
   * Proxy support (with authentication)
   * Host authentication (Basic)
   * Watches for "bogus" OK responses
   * Attempts to perform educated guesses for Authentication realms
   * Captures/prints any Cookies received
   * Mutate mode to "go fishing" on web servers for odd items
   * Builds Mutate checks based on robots.txt entries (if present)
   * Scan multiple ports on a target to find web servers (can integrate nmap for speed, if available)
   * Multiple IDS evasion techniques
   * Users can add a custom scan database
   * Supports automatic code/check updates (with web access)
   * Multiple host/port scanning (scan list files)
   * Username guessing plugin via the cgiwrap program and Apache ~user methods 


Version 2

Nikto version 2 contains many enhancements over the first version. Some of the major new features include:

   * Fingerprinting web servers via favicon.ico files
   * 404 checking for each file type
   * Enhanced false positive reduction via multiple methods: headers, page content, and content hashing
   * Scan tuning to include or exclude entire classes of vulnerability checks
   * Expanded scan database can have multiple positive or negative triggers, to allow AND/OR/NOT for flexible checks
   * Uses LibWhisker 2, which has its own long list of enhancements
   * A "single" scan mode that allows you to craft an HTTP request by hand
   * Updated and greatly enhanced documentation
   * Authorization guessing handles any directory, not just the root directory
   * New HTML report
   * Basic template engine so that HTML reports can be easily customized
   * An experimental knowledge base for scans, which will allow regenerated reports and retests (future)
   * ... and countless tweaks/bugfixes/optimizations ... 


Download

http://cirt.net/nikto/nikto-current.tar.gz


NiktoFE

Nikto was ported to GUI version by Aung Khant (http://yehg.net). You can get it from http://yehg.net/lab/pr0js/files.php/NiktoFEv01.zip


References

http://cirt.net/nikto2