官术网_书友最值得收藏!

Nikto

Nikto is a Linux-based website vulnerability scanner that hackers use to identify any exploitable loopholes in organizational websites. The tool scans the web servers for over 6,800 commonly exploited vulnerabilities. It also scans for unpatched versions of servers on over 250 platforms. The tool also checks for errors in the configurations of files in web servers. The tool is, however, not very good at masking its tracks, and thus almost always gets picked up by any intrusion detection and prevention system.

Nikto works through a set of command-line interface commands. Users first give it the IP address of the website that they wish to scan. The tool will do an initial scan and give back details about the web server.

From there, users can issue more commands to test for different vulnerabilities on the web server. Figure 8 shows a screenshot of the Nikto tool scanning a web server for vulnerabilities. The command issued to give this output is:

    Nikto -host 8.26.65.101
Figure 8: Screenshot of the Nikto tool looking for vulnerabilities in a Microsoft-IIS web server
主站蜘蛛池模板: 霍山县| 南投县| 睢宁县| 高唐县| 建宁县| 田阳县| 通许县| 靖远县| 江门市| 花莲市| 江都市| 中山市| 佛坪县| 迁安市| 松阳县| 灵川县| 沂源县| 沙坪坝区| 金塔县| 寿宁县| 丰都县| 剑阁县| 双牌县| 红河县| 北辰区| 阿拉善盟| 淮安市| 子洲县| 来安县| 阿勒泰市| 宜川县| 仙居县| 合作市| 台前县| 临汾市| 藁城市| 上蔡县| 睢宁县| 罗江县| 潍坊市| 绥阳县|