Nikto — Сканер безопасности веб-сервера

Что это

Nikto — это подключаемый веб-сервер и CGI-сканер, написанный на Perl и использующий LibWhisker от RFP для выполнения быстрых проверок безопасности или информации.

Оригинал описания (EN)

Nikto is a pluggable web server and CGI scanner written in Perl, using rfp’s LibWhisker to perform fast security or informational checks.

Пример использования

root@kali:~# nikto -h

Options: -Add-header Add HTTP headers (can be used multiple times, one per header pair) -ask+ Whether to ask about submitting updates yes Ask about each (default) no Don't ask, don't send auto Don't ask, just send -check6 Check if IPv6 is working (connects to ipv6.google.com or value set in nikto.conf) -Cgidirs+ Scan these CGI dirs: "none", "all", or values like "/cgi/ /cgi-a/" -config+ Use this config file -Display+ Turn on/off display outputs: 1 Show redirects 2 Show cookies received 3 Show all 200/OK responses 4 Show URLs which require authentication D Debug output E Display all HTTP errors P Print progress to STDOUT S Scrub output of IPs and hostnames V Verbose output -dbcheck Check database and other key files for syntax errors -evasion+ Encoding technique: 1 Random URI encoding (non-UTF8) 2 Directory self-reference (/./) 3 Premature URL ending 4 Prepend long random string 5 Fake parameter 6 TAB as request spacer 7 Change the case of the URL

Пакеты и установка

nikto

Сканер безопасности веб-сервера
Установка: sudo apt install nikto

Официальная документация

https://www.kali.org/tools/nikto/

Комментарии