Terminal Dojo
Help العربية Sign inGet started

Command library / nikto

nikto

BashDraft — pending expert review3 practice missions

Scan a web server for known vulnerabilities and misconfigurations

Runs thousands of checks against a web server: dangerous files, outdated software versions, default credentials, misconfigured headers. -h (host) is the only required flag; nikto assumes HTTP on port 80 unless you tell it otherwise.

Practice nikto

Usage

nikto -h target [-p port] [-ssl]
Scope: Only against systems you own or are explicitly authorised to test. Nikto is loud and unmistakable in access logs — assume the target WILL notice.

Options and flags

Examples

Common mistakes

nikto 10.10.10.5 nikto -h 10.10.10.5

The target is never a bare argument — nikto always needs it introduced with -h.

Related commands

nmapgobuster