Nikto: web server scanner

Nikto is an Open Source web server scanner which performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files/CGIs, checks for outdated versions of over 1000 servers, and version specific problems on over 270 servers. It also checks for server configuration items such as the presence of multiple index files, HTTP server options, and will attempt to identify installed web servers and software. Nikto is not designed as an overly stealthy tool. It will test a web server in the quickest time possible, and is fairly obvious in log files. Some of the major features of Nikto:

  • SSL Support
  • Full HTTP proxy support
  • Checks for outdated server components
  • Save reports in plain text, XML, HTML, NBE or CSV
  • Template engine to easily customize reports
  • Scan multiple ports on a server, or multiple servers via input file
  • Easily updates via command line
  • Identifies installed software via headers, favicons and files
  • Host authentication with Basic and NTLM
  • Mutation techniques to “fish” for content on web servers
  • Scan tuning to include or exclude entire classes of vulnerability
    checks
  • Enhanced false positive reduction via multiple methods: headers,
    page content, and content hashing
  • A “single” scan mode that allows you to craft an HTTP request by
    hand
  • Reports “unusual” headers seen
  • Interactive status, pause and changes to verbosity settings

Leave a Reply