Skip to content

Instantly share code, notes, and snippets.

@awesomeaakash
Created August 19, 2017 13:38
Show Gist options
  • Select an option

  • Save awesomeaakash/cb85d7463b4a97c7df61629ddfeeb15b to your computer and use it in GitHub Desktop.

Select an option

Save awesomeaakash/cb85d7463b4a97c7df61629ddfeeb15b to your computer and use it in GitHub Desktop.

Revisions

  1. awesomeaakash created this gist Aug 19, 2017.
    32 changes: 32 additions & 0 deletions nikto scan
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,32 @@
    ─[root@vampy]─[~/Desktop]
    └──╼ #nikto -h 192.168.56.131
    - Nikto v2.1.6
    ---------------------------------------------------------------------------
    + Target IP: 192.168.56.131
    + Target Hostname: 192.168.56.131
    + Target Port: 80
    + Start Time: 2017-08-18 21:12:18 (GMT5.5)
    ---------------------------------------------------------------------------
    + Server: Apache/2.4.7 (Ubuntu)
    + Server leaks inodes via ETags, header found with file /, fields: 0x2b 0x5200b3f35ee65
    + The anti-clickjacking X-Frame-Options header is not present.
    + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
    + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
    + No CGI Directories found (use '-C all' to force check all possible dirs)
    + Entry '/index.html?' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + Entry '/?/' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + Entry '/?hl=/' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + Entry '/?hl=*&/' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + Entry '/?hl=*&gws_rd=ssl$/' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + Entry '/?hl=*&*&gws_rd=ssl/' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + Entry '/?gws_rd=ssl$/' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + Entry '/?pt1=true$/' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + Entry '/Setec/' in robots.txt returned a non-forbidden or redirect HTTP code (200)
    + "robots.txt" contains 299 entries which should be manually viewed.
    + Apache/2.4.7 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
    + Allowed HTTP Methods: GET, HEAD, POST, OPTIONS
    + OSVDB-3233: /icons/README: Apache default file found.
    + 7849 requests: 0 error(s) and 17 item(s) reported on remote host
    + End Time: 2017-08-18 21:12:39 (GMT5.5) (21 seconds)
    ---------------------------------------------------------------------------
    + 1 host(s) tested