【2014-04-28】kali下使用nikto扫描网站

📅 2026/8/18 19:14:05
【2014-04-28】kali下使用nikto扫描网站
[历史归档]本文原发布于 cstriker1407.info 个人博客内容为历史存档仅供参考。发布时间2014-04-28 标题kali下使用nikto扫描网站分类操作系统 / 安全 标签kali·niktokali下使用nikto扫描网站nikto帮助文档nikto使用示例漏洞使用笔记仅供学习交流使用请勿进行其他用途参考【 http://www.computersecuritystudent.com/SECURITY_TOOLS/DVWA/DVWAv107/lesson13/index.html 】nikto帮助文档帮助文档比较复杂这里就使用最简单的几种方法:rootkali:~# nikto -HOptions: -ask Whether to ask about submitting updatesyesAsk about each(default)no Dont ask, dont send auto Dont ask, just send -Cgidirs Scan these CGI dirs: none, all, or values like /cgi/ /cgi-a/ -config Use this config file -Display Turn on/off display outputs: 1 Show redirects 2 Show cookies received 3 Show all 200/OK responses 4 Show URLs which require authentication D Debug output E Display all HTTP errors P Print progress to STDOUT S Scrub output of IPs and hostnames V Verbose output -dbcheck Check database and other key files for syntax errors -evasion Encoding technique: 1 Random URI encoding (non-UTF8) 2 Directory self-reference (/./) 3 Premature URL ending 4 Prepend long random string 5 Fake parameter 6 TAB as request spacer 7 Change the case of the URL 8 Use Windows directory separator (\) A Use a carriage return (0x0d) as a request spacer B Use binary value 0x0b as a request spacer -Format Save file (-o) format: csv Comma-separated-value htm HTML Format msf Log to Metasploit nbe Nessus NBE format txt Plain text xml XML Format (if not specified the format will be taken from the file extension passed to -output) -Help Extended help information -host Target host -IgnoreCode Ignore Codes--treat as negative responses -id Host authentication to use, format is id:pass or id:pass:realm -key Client certificate key file -list-plugins List all available plugins, perform no testing -maxtime Maximum testing time per host -mutate Guess additional file names: 1 Test all files with all root directories 2 Guess for password file names 3 Enumerate user names via Apache (/~user type requests) 4 Enumerate user names via cgiwrap (/cgi-bin/cgiwrap/~user type requests) 5 Attempt to brute force sub-domain names, assume that the host name is the parent domain 6 Attempt to guess directory names from the supplied dictionary file -mutate-options Provide information for mutates -nointeractive Disables interactive features -nolookup Disables DNS lookups -nossl Disables the use of SSL -no404 Disables nikto attempting to guess a 404 page -output Write output to this file (. for auto-name) -Pause Pause between tests (seconds, integer or float) -Plugins List of plugins to run (default: ALL) -port Port to use (default 80) -RSAcert Client certificate file -root Prepend root value to all requests, format is /directory -Save Save positive responses to this directory (.forauto-name)-sslForce ssl mode on port -Tuning Scan tuning:1Interesting File / Seeninlogs2Misconfiguration / Default File3Information Disclosure4Injection(XSS/Script/HTML)5Remote File Retrieval - Inside Web Root6Denial of Service7Remote File Retrieval - Server Wide8Command Execution / Remote Shell9SQL Injection0File Upload a Authentication Bypass b Software Identification c Remote Source Inclusion x Reverse Tuning Options(i.e., include all except specified)-timeout Timeoutforrequests(default10seconds)-UserdbsLoad only user databases, not the standard databases all Disable standard dbs and load only user dbs tests Disable only db_tests and load udb_tests-untilRununtilthe specifiedtimeor duration-updateUpdate databases and plugins from CIRT.net-useproxyUse the proxy definedinnikto.conf-VersionPrint plugin and database versions -vhost Virtualhost(for Host header) requires a valuenikto使用示例使用前需要更新nikto输入命令nikto-update但有时候会出现网路问题作者这里这样处理的如下不知道对不对。rootkali:~# nikto -update Retrievingdb_tests ERROR: Unable to get CIRT.net/nikto/UPDATES/2.1.5/db_tests首先查找文件【 db_tests 】rootkali:~# cd /rootkali:/# find . -name db_tests./usr/share/webshag/database/nikto/db_tests ./var/lib/nikto/databases/db_tests然后删掉文件重新更新就可以了rootkali:/# cd /var/lib/nikto/databases/rootkali:/var/lib/nikto/databases# rm db_testsrootkali:/var/lib/nikto/databases# nikto -update Retrievingdb_tests CIRT.net message: Please submit Nikto bugs to http://trac2.assembla.com/Nikto_2/report/2如果还是不行就手动下载rootkali:/var/lib/nikto/databases# wget CIRT.net/nikto/UPDATES/2.1.5/db_tests更新好之后就可以扫描了rootkali:/var/lib/nikto/databases# nikto -host http://192.168.168.109/DVWA-1.0.8- Nikto v2.1.5 --------------------------------------------------------------------------- Target IP:192.168.168.109 Target Hostname:192.168.168.109 Target Port:80 Start Time:2014-04-2823:08:40(GMT8)--------------------------------------------------------------------------- Server: Apache/2.4.9(Unix)OpenSSL/1.0.1g PHP/5.5.11 mod_perl/2.0.8-dev Perl/v5.16.3 Retrieved x-powered-by header: PHP/5.5.11 The anti-clickjacking X-Frame-Options header is not present. Cookie PHPSESSID created without the httponly flag Cookie security created without the httponly flag Root page / redirects to: login.php No CGI Directories found(use-C allto force check all possibledirs) Server leaks inodes via ETags, header found withfile/DVWA-1.0.8/robots.txt, fields: 0x1a 0x4dba8594c3d80 File/dir/inrobots.txt returned a non-forbidden or redirect HTTP code(302)robots.txtcontains1entrywhichshould be manually viewed. Allowed HTTP Methods: POST, OPTIONS, GET, HEAD, TRACE OSVDB-877: HTTP TRACE method is active, suggesting thehostis vulnerable to XST OSVDB-3268: /DVWA-1.0.8/config/: Directory indexing found. /DVWA-1.0.8/config/: Configuration information may be available remotely. OSVDB-3268: /DVWA-1.0.8/docs/: Directory indexing found. /DVWA-1.0.8/login.php: Admin login page/section found. 6545items checked:0error(s)and13item(s)reported on remotehost End Time:2014-04-2823:09:03(GMT8)(23seconds)--------------------------------------------------------------------------- 1host(s)tested漏洞使用877漏洞rootkali:/var/lib/nikto/databases# telnet 192.168.168.109 80Trying192.168.168.109... Connected to192.168.168.109. Escape character is^].get index.html 。。。。。。 。。。。。。ahref/localhost/abr /spanApache/2.4.9(Unix)OpenSSL/1.0.1g PHP/5.5.11 mod_perl/2.0.8-dev Perl/v5.16.3/span/address/body/htmlConnection closed by foreign host.服务器的配置信息暴露了~~3268漏洞查看网页参看服务器端果然有这个文件。