How To Scan website vulnerabilities using nikto

Disclaimer – Our tutorials are designed to aid aspiring pen testers/security enthusiasts in learning new skills, we only recommend that you test this tutorial on a system that belongs to YOU. We do not accept responsibility for anyone who thinks it’s a good idea to try to use this to attempt to hack systems that do not belong to you

Step 1: Fire Up Kali & Open Nikto

Let’s fire up Kali and get started with nikto. Once we have Kali up and running, go to Kali
Linux -> Vulnerability Analysis ->Misc Scanners -> nikto, like in the screenshot below.

Step 2: Scan the Web Server

Let’s start with a safe web server on our own network. In this case, I have started the http service on another machine on my network. There is not a website hosted by this machine, just the web server. Let’s scan it for vulnerabilities by typing:
  • nikto -h
Nikto responds with a lot of information, as you can see below.

First, it tells us the server is Apache 2.2.14, probably on Ubuntu. It nailed this info and gives up more information on other potential vulnerabilities on this web server.
Note near the bottom that it identifies some vulnerabilities with the OSVDB prefix. This is the Open Source Vulnerability Database. This is a database maintained of known vulnerabilities at, in addition to other databases I covered, such as SecurityFocus and Microsoft’s Technet.

Step 3: Scan the Site

Let’s try another site.  Let’s see what nikto can tell us about this site.
  • nikto -h

Once again, it identifies the server (Apache) and then proceeds to identify numerous potential vulnerabilities pre-fixed with OSVDB. We can take a look at that website at to learn more about these vulnerabilities.

Now, let’s use this site to find information on one of the vulnerabilities identified by nikto as OSVDB-877. We can put that reference number into the search function and it retrieves the following page.

How To Scan website vulnerabilities using nikto How To Scan website vulnerabilities using nikto Reviewed by Krutik on 00:12:00 Rating: 5

No comments:

Powered by Blogger.