nikto cheat sheet

Nikto is a web server assessment tool, designed to identify and analyze various default and insecure files, configurations, and programs on just about any type of web server.

Target Specification Switch Example Description nmap Scan a single IP nmap Scan specific IPs nmap Scan a range nmap Scan a domain nmap Scan using CIDR notation -iL nmap -iL targets.txt Scan targets from a file -iR nmap -iR 100 Scan 100 random hosts --exclude nmap --exclude Exclude […] sqlmap Cheat Sheet Sqlmap scanner cheat sheet.

Nikto -h -dbcheck, Config file

Below is a helpful infographic for basic commands and usage with the tool Nikto.

a   Authentication Bypass D Show debug output txt       Plain text Open the nikto.conf file in the location /etc/nikto.conf; Search for the text STATIC-COOKIE and add your cookie and its value like the image below. Scans for http (Web) servers on port 80 and pipes into Nikto for scanning. Now that we have added the cookie you might want to proxy it through burpsuite to verify the traffic that nikto generates.

1 Random URI Encoding 5 Fake parameter man sqlmap can also be used on Kali.
1   Test all files in root directory
b   Software Identification V Verbose output, Nikto -h  -evasion

