Nikto web server scanner

来源:互联网 发布:吴佩频道知乎 编辑:程序博客网 时间:2024/06/05 00:29

OS :kali Linux
Tool:nikto
Do-what: Simple Web Server Scan using nikto

process:

root@kali:/# nikto -C all -h http://www.landgrey.cn- Nikto v2.1.6---------------------------------------------------------------------------+ Target IP:          120.27.108.113+ Target Hostname:    www.landgrey.cn+ Target Port:        80+ Start Time:         2016-10-10 15:56:53 (GMT8)---------------------------------------------------------------------------+ Server: nginx+ Server leaks inodes via ETags, header found with file /, fields: 0x57eb1326 0x3e1 + The anti-clickjacking X-Frame-Options header is not present.+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type+ Entry '/howfunitis/' in robots.txt returned a non-forbidden or redirect HTTP code (200)+ "robots.txt" contains 1 entry which should be manually viewed.+ ERROR: Error limit (20) reached for host, giving up. Last error: error reading HTTP response+ Scan terminated:  13 error(s) and 6 item(s) reported on remote host+ End Time:           2016-10-10 15:59:16 (GMT8) (143 seconds)---------------------------------------------------------------------------+ 1 host(s) tested

有趣的是,nikto检测出我在robots.txt中故意设置的一个彩蛋。

0 0