官术网_书友最值得收藏!

Nikto

Nikto is a Linux-based website vulnerability scanner that hackers use to identify any exploitable loopholes in organizational websites. The tool scans the web servers for over 6,800 commonly exploited vulnerabilities. It also scans for unpatched versions of servers on over 250 platforms. The tool also checks for errors in the configurations of files in web servers. The tool is, however, not very good at masking its tracks, and thus almost always gets picked up by any intrusion detection and prevention system.

Nikto works through a set of command-line interface commands. Users first give it the IP address of the website that they wish to scan. The tool will do an initial scan and give back details about the web server.

From there, users can issue more commands to test for different vulnerabilities on the web server. Figure 8 shows a screenshot of the Nikto tool scanning a web server for vulnerabilities. The command issued to give this output is:

    Nikto -host 8.26.65.101
Figure 8: Screenshot of the Nikto tool looking for vulnerabilities in a Microsoft-IIS web server
主站蜘蛛池模板: 金平| 灵寿县| 崇州市| 定远县| 柳河县| 赣州市| 黄骅市| 和龙市| 九龙城区| 阜平县| 抚顺县| 奇台县| 襄垣县| 弥勒县| 北流市| 宁强县| 金塔县| 资溪县| 饶河县| 马鞍山市| 湘乡市| 昆山市| 苗栗县| 东宁县| 威海市| 广河县| 武胜县| 梧州市| 兰西县| 通江县| 旌德县| 华阴市| 乌鲁木齐县| 保靖县| 城固县| 梧州市| 浦江县| 秭归县| 吴江市| 客服| 延川县|