Nikto 웹 서버 스캐너
Nikto 웹 서버 스캐너 - https://cirt.net/Nikto2
전체 문서 - https://github.com/sullo/nikto/wiki
일반 실행:
git clone https://github.com/sullo/nikto
# Main script is in program/
cd nikto/program
# Run using the shebang interpreter
./nikto.pl -h http://www.example.com
# Run using perl (if you forget to chmod)
perl nikto.pl -h http://www.example.com
Docker Hub에서 Docker 컨테이너로 실행:
docker pull hackllc/nikto:latest
또는 ghcr.io에서:
docker pull ghcr.io/sullo/nikto:latest
Dockerfile에서 Docker 컨테이너로 실행:
git clone https://github.com/sullo/nikto.git
cd nikto
docker build -t hackllc/nikto .
# Call it without arguments to display the full help
docker run --rm hackllc/nikto
# Basic usage
docker run --rm hackllc/nikto -h http://www.example.com
# To save the report in a specific format, mount /tmp as a volume:
docker run --rm -v $(pwd):/tmp hackllc/nikto -h http://www.example.com -o /tmp/out.json
기본 사용법:
Options:
-Add-header Add HTTP headers (can be used multiple times, one per header pair)
-ask+ Whether to ask about submitting updates
yes Ask about each (default)
no Don't ask, don't send
auto Don't ask, just send
-check6 Check if IPv6 is working (connects to ipv6.google.com or value set in nikto.conf)
-Cgidirs+ Scan these CGI dirs: "none", "all", or values like "/cgi/ /cgi-a/"
-config+ Use this config file
-Display+ Turn on/off display outputs:
1 Show redirects
2 Show cookies received
3 Show all 200/OK responses
4 Show URLs which require authentication
D Debug output
E Display all HTTP errors
P Print progress to STDOUT
S Scrub output of IPs and hostnames
V Verbose output
-dbcheck Check database and other key files for syntax errors
-evasion+ Encoding technique:
1 Random URI encoding (non-UTF8)
2 Directory self-reference (/./)
3 Premature URL ending
4 Prepend long random string
5 Fake parameter
6 TAB as request spacer
7 Change the case of the URL
8 Use Windows directory separator (\)
A Use a carriage return (0x0d) as a request spacer
B Use binary value 0x0b as a request spacer
-followredirects Follow 3xx redirects to new location
-Format+ Save file (-o) format. Can specify multiple formats separated by commas (e.g., htm,sql,txt,json,xml):
csv Comma-separated-value
json JSON Format
htm HTML Format
sql Generic SQL (see docs for schema)
sqld SQL Direct (directly inserts into MySQL/PostgreSQL database)
txt Plain text
xml XML Format
(if not specified the format will be taken from the file extension passed to -output)
Note: sqld format requires DB_TYPE, DB_HOST, DB_PORT, DB_NAME in nikto.conf
and NIKTO_DB_USER, NIKTO_DB_PASS environment variables
-Help This help information
-host+ Target host/URL
-id+ Host authentication to use, format is id:pass or id:pass:realm
-ipv4 IPv4 Only
-ipv6 IPv6 Only
-key+ Client certificate key file
-list-plugins List all available plugins, perform no testing
-maxtime+ Maximum testing time per host (e.g., 1h, 60m, 3600s)
-mutate+ Guess additional file names:
1 Test all files with all root directories
2 Guess for password file names
3 Enumerate user names via Apache (/~user type requests)
4 Enumerate user names via cgiwrap (/cgi-bin/cgiwrap/~user type requests)
5 Attempt to brute force sub-domain names, assume that the host name is the parent domain
6 Attempt to guess directory names from the supplied dictionary file
-mutate-options Provide information for mutates
-nocheck Don't check for updates on startup
-nocookies Do not use cookies from responses in requests (cookies are stored and sent by default)
-nointeractive Disables interactive features
-nolookup Disables DNS lookups
-noslash Strip trailing slash from URL (e.g., '/admin/' to '/admin')
-nossl Disables the use of SSL
-no404 Disables nikto attempting to guess a 404 page
-Option Over-ride an option in nikto.conf, can be issued multiple times
-output+ Write output to this file ('.' for auto-name)
-Pause+ Pause between tests (seconds)
-Platform+ Platform of target (nix, win, all)
-Plugins+ List of plugins to run (default: ALL)
-port+ Port to use (default 80)
-RSAcert+ Client certificate file
-root+ Prepend root value to all requests, format is /directory
-Save Save positive responses to this directory ('.' for auto-name)
-ssl Force ssl mode on port
-Tuning+ Scan tuning:
1 Interesting File / Seen in logs
2 Misconfiguration / Default File
3 Information Disclosure
4 Injection (XSS/Script/HTML)
5 Remote File Retrieval - Inside Web Root
6 Denial of Service
7 Remote File Retrieval - Server Wide
8 Command Execution / Remote Shell
9 SQL Injection
0 File Upload
a Authentication Bypass
b Software Identification
c Remote Source Inclusion
d WebService
e Administrative Console
x Reverse Tuning Options (i.e., include all except specified)
-timeout+ Timeout for requests (default 10 seconds)
-Userdbs Load only user databases, not the standard databases
all Disable standard dbs and load only user dbs
tests Disable only db_tests and load udb_tests
-useragent Force User-Agent instead of pulling from database
-url+ Target host/URL (alias of -host)
-useproxy Use the proxy defined in nikto.conf, or argument http://server:port
-Version Print plugin and database versions
-vhost+ Virtual host (for Host header)
-404code Ignore these HTTP codes as negative responses (always). Format is "302,301".
-404string Ignore this string in response body content as negative response (always). Can be a regular expression.
+ requires a value
Nikto의 테스트 데이터베이스는 응답을 매칭하기 위한 미니 DSL을 지원합니다. 지원되는 매처는 다음과 같습니다:
BODY: 및 !BODY: — 응답 본문에서 콘텐츠를 매칭하거나 제외합니다.HEADER: 및 !HEADER: — HTTP 헤더에서 콘텐츠를 매칭하거나 제외합니다.COOKIE: 및 !COOKIE: — HTTP 쿠키에서 콘텐츠를 매칭하거나 제외합니다. (신규)CODE: 및 !CODE: — HTTP 상태 코드를 매칭하거나 제외합니다.여러 매처를 &&(AND)로 결합할 수 있습니다. 예시:
BODY:login&&!BODY:logout&&HEADER:X-Powered-By&&COOKIE:sessionid
이 조건은 응답 본문에 "login"이 포함되고 "logout"이 포함되지 않으며, 헤더에 "X-Powered-By"가 있고 "sessionid"라는 이름의 쿠키가 있는 경우 매칭됩니다.
저작권 (C) 2001–2026 Chris Sullo. 모든 권리 보유.
이 라이선스 고지는 Nikto의 코드에만 적용됩니다.
LibWhisker 라이선스 정보는 COPYING.LibWhisker를 참조하십시오.
데이터베이스 파일은 GPL에 따라 라이선스가 부여되지 않으며, 공식 Nikto 패키지 또는 설치 프로그램의 일부로만 배포할 수 있고 Nikto 전용으로만 사용할 수 있습니다.
전체 라이선스 조건 및 상업적 사용 정책은 다음을 방문하십시오: https://cirt.net/Nikto-Licensing
이 프로그램은 자유 소프트웨어입니다: Free Software Foundation이 발표한 GNU General Public License 버전 3의 조건에 따라 이 프로그램을 재배포하거나 수정할 수 있습니다.
이 프로그램은 유용할 것이라는 희망으로 배포되지만, 어떠한 보증도 없습니다. 상품성 또는 특정 목적 적합성에 대한 묵시적 보증조차 없습니다. 자세한 내용은 GNU General Public License를 참조하십시오.
전체 라이선스 전문은 https://www.gnu.org/licenses/gpl-3.0.txt에서 확인할 수 있습니다.
전체 라이선스 고지는 COPYING을 참조하십시오.