We have discussed about Nikto in detail here

Nikto is an Open Source web server scanner which performs comprehensive tests against web servers for multiple items, including over 6100 potentially dangerous files/CGIs, checks for outdated versions of over 950 servers, and version specific problems on over 260 servers. It also checks for server configuration items such as the presence of multiple index files, HTTP server options, and will attempt to identify installed web servers and software. Scan items and plugins are frequently updated and can be automatically updated.

List of changes made in Nikto 2.1.1:
- Fixed SKIPPORTS
- Moved User-Agent string to nikto.conf
- Added dynamic variables to User-Agent (Testid, Evasion methods)
- Added support for OSVDB, now the fun bit of filling it in
- Basic syntax checks for all databases
- Added an extra optional element to xml output to contain the SSL date. Need to do similar for html, txt and csv
- Shorts authentication being successful if an error is returned
- Support for short reads in LW2.5
- If -Format is missed guess the format based on file extension in -output. Default is none if -output is omitted.
- Multiple index file enhancements for groups and better unique file identification
- Content in xml report is now wrapped in CDATA
- Mutate now respects db variables
- Fix for response caching
- Spelling disagreements between Brits and Americans
- Added @RFIURL to nikto.conf for a remote file include location, and supporting code.
- Added ~2300 RFI tests from the combined RSnake/OSVDB list
- Removed NMAP and NMAPOPTS from nikto.conf as it is no longer used/supported
- Reporting: simplify xml/html code, fix a bug when a space is in the uri, and load ony needed templates
- Upgrade to LibWhisker 2.5
- Enable 2 new LW evasion tacticts (carriage return or binary value as request spacer)
- Added support to select plugins via -Plugins and -list-plugins option to list current plugins
- Major bug fix for proxy usage
- Don’t report p3p header as unusual
- Various changes to aid future binary db usage for mutates
- Various changes to aid future multi-threading
- Fix for multiple index files

Video tutorial how to use Nikto:

Download Nikto version 2.1.1here

Searches leading to this post:
nikto tutorial, nikto 2 example, nikto 2 tutorial

If you enjoyed this article, you might also like:

  • July 12, 2010 -- UPDATE: Nikto v2.1.2!
    We have discussed about Nikto in detail here. Now, after almost four months, a new version - Nikto v...
  • January 15, 2010 -- List of Free Web Application Scanners!
    I was on another site helping someone with the available options on FREE Web Application Scanners. W...
  • October 20, 2009 -- Update : Nikto 2.1.0
    Nikto is an Open Source web server scanner which performs comprehensive tests against web servers fo...
  • August 20, 2010 -- UPDATE: XSSer v0.7a!
    All of you web application penetration testers, check out this release of XSSer version 0.7a, for i...
  • July 2, 2010 -- UPDATE: XSSer v0.6a!
    All of you web application penetration testers, check out this release of XSSer version 0.6a, for i...
  • April 19, 2010 -- UPDATE: XSSer v0.5a!
    All of you web application penetration testers, check out this release of XSSer version 0.5a!“C...
  • April 9, 2010 -- CMS Explorer: Know More About Different CMS!
    One of the authors of Nikto - Chris Sullo, has come up with CMS Explorer. It is designed to reveal t...
  • March 21, 2010 -- UPDATE: XSSer v0.4a!
    See! This is what we say about an actively maintained project! We wrote about XSSer just yesterday ...
  • March 20, 2010 -- XSSer: Automate your XSS Injections!
    If you are aware, we posted about XSSPloit almost a year ago. Since then, we have bought to you too...

Previous post:

Next post: