官术网_书友最值得收藏!

Nikto

Nikto is a Linux-based website vulnerability scanner that hackers use to identify any exploitable loopholes in organizational websites. The tool scans the web servers for over 6,800 commonly exploited vulnerabilities. It also scans for unpatched versions of servers on over 250 platforms. The tool also checks for errors in the configurations of files in web servers. The tool is, however, not very good at masking its tracks, and thus almost always gets picked up by any intrusion detection and prevention system.

Nikto works through a set of command-line interface commands. Users first give it the IP address of the website that they wish to scan. The tool will do an initial scan and give back details about the web server.

From there, users can issue more commands to test for different vulnerabilities on the web server. Figure 8 shows a screenshot of the Nikto tool scanning a web server for vulnerabilities. The command issued to give this output is:

    Nikto -host 8.26.65.101
Figure 8: Screenshot of the Nikto tool looking for vulnerabilities in a Microsoft-IIS web server
主站蜘蛛池模板: 新龙县| 南开区| 永顺县| 建阳市| 聂拉木县| 运城市| 郯城县| 新乡市| 万州区| 巍山| 巍山| 东乡| 皮山县| 秦皇岛市| 德安县| 饶平县| 龙州县| 永泰县| 祁东县| 抚顺县| 抚顺县| 绍兴县| 沁源县| 曲阳县| 民丰县| 邵阳市| 全南县| 满城县| 五峰| 色达县| 桦南县| 哈密市| 托里县| 衡阳县| 石楼县| 绥阳县| 嵊泗县| 新津县| 泊头市| 都昌县| 渭南市|