Softpedia
 


SCRIPTS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
WEEK'S BEST
  • PeoplePods 0.9
  • Brackets Sprint 8
  • elFinder 2.0 RC1
  • BBClone 0.6.1
  • Twitter Follow Box...
  • Multilingual Press...
  • SimplePie 1.2.1
  • TinyTips 1.2
  • SWFUpload 2.2.0.1 ...
  • Head Cleaner 1.4.2.9
  • Home > Scripts > Security Systems

    Nikto 2.1.4

    Download button


    Downloads: 326  Tell us about an update
    User Rating:
    Rated by:
    NOT RATED
    0 user(s)
    Developer:

    Website:

    License / Price:

    Platforms:

    Databases:

    Language:

    Last Updated:

    Category:
    Chris Sullo and David Lodge | More scripts
    cirt.net
    GPL - GNU General Public License 

    Windows / Linux / Mac OS / BSD / Solaris
    N/A
    Perl
    August 12th, 2011, 17:55 GMT [view history]
    C: \ Security Systems

     Read user reviews (0)  Refer to a friend  Subscribe

    Nikto description

    This is a web server scanner, which looks for common security loopholes

    Nikto performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files/CGIs, checks for outdated versions of over 1200 servers, and version specific problems on over 270 servers.

    Nikto is written in Perl and verifies server configurations for duplicate index files, HTTP server options and installed web server software.

    It provides feedback, allowing admins to have their server up to date at all time.

    Here are some key features of "Nikto":

    · SSL Support (Unix with OpenSSL or maybe Windows with ActiveState's Perl/NetSSL)
    · Full HTTP proxy support
    · Checks for outdated server components
    · Save reports in plain text, XML, HTML, NBE or CSV
    · Template engine to easily customize reports
    · Scan multiple ports on a server, or multiple servers via input file (including nmap output)
    · LibWhisker's IDS encoding techniques
    · Easily updated via command line
    · Identifies installed software via headers, favicons and files
    · Host authentication with Basic and NTLM
    · Subdomain guessing
    · Apache and cgiwrap username enumeration
    · Mutation techniques to "fish" for content on web servers
    · Scan tuning to include or exclude entire classes of vulnerability checks
    · Guess credentials for authorization realms (including many default id/pw combos)
    · Authorization guessing handles any directory, not just the root directory
    · Enhanced false positive reduction via multiple methods: headers, page content, and content hashing
    · A "single" scan mode that allows you to craft an HTTP request by hand
    · Reports "unusual" headers seen
    · Interactive status, pause and changes to verbosity settings
    · Logging to Metasploit
    · Thorough documentation

    What's New in This Release: [ read full changelog ]

    · Parsing of nmap greppable output now checks any port description matching http
    · Fix a potential for false positives or negatives with version matches
    · Not all udb* files were loaded properly
    · Server name not properly printed in update/submission output
    · Variable consolidation & memory usage cleanup
    · Move message on -root from notices to target host info (suggestion from YGN)
    · Automatically escape invalid regexes in databases at run-time, so no dying
    · Added nikto_ssl.plugin to check cert's CN vs hostname
    · Add basic retry on error in nfetch()
    · Change how db_404_strings are used by moving where they are checked to reduce FP
    · Fix missing url sent to rm_active_content during error mapping--should prevent many FPs
    · Make nikto_multiple_index.plugin only look at 200 responses



    TAGS:

    server scanner | server security | server config | scan | server | security



    HTML code for linking to this page:


    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM