Nikto Web Vulnerability Scanner: Here Are Some of The Cool Things That Nikto Can Do
Nikto Web Vulnerability Scanner: Here Are Some of The Cool Things That Nikto Can Do
Websites are a critical part of almost every business or organization in the world. From your nearby florist to
global brands, almost everyone uses a website as part of their branding.
Unfortunately, websites are also one of the most unsecured gateways through which an attacker can exploit your
company.
Since most websites are not backed by strong technical teams, it is important to understand website and web
application security to protect your organization.
Nikto can perform comprehensive tests against web servers for multiple security threats, including over 6700
potentially dangerous files/programs. Nikto can also perform checks for outdated web servers software, and
version-specific problems.
Nikto is a free software command-line vulnerability scanner that scans webservers for dangerous files/CGIs,
outdated server software and other problems. It performs generic and server type specific checks. It also
captures and prints any cookies received.
Here are some of the cool things that Nikto can do:
Find SQL injection, XSS, and other common vulnerabilities
Guess subdomains
Check for server configuration items like multiple index files, HTTP server options, and so on
Exports to Metasploit
Open source
How to Scan a Domain with SSL Enabled
For domains with HTTPS enabled, you have to specify the -ssl flag to scan port 443:
> nikto -h https://nmap.org -ssl
Let's assume we have a file named domains.txt with two domain names:
scanme.nmap.org
nmap.org.
To scan both of them with Nikto, run the following command: