Command library / nikto
nikto
Scan a web server for known vulnerabilities and misconfigurations
Runs thousands of checks against a web server: dangerous files, outdated software versions, default credentials, misconfigured headers. -h (host) is the only required flag; nikto assumes HTTP on port 80 unless you tell it otherwise.
Practice niktoUsage
nikto -h target [-p port] [-ssl]
Scope: Only against systems you own or are explicitly authorised to test. Nikto is loud and unmistakable in access logs — assume the target WILL notice.
Options and flags
-h, --hostTARGETthe target host name, IP or URL — required
-p, --portPORTport to scan (default 80)
-sslforce an SSL/TLS connection (HTTPS)
-o, --outputFILEsave the results to a file
Examples
nikto -h http://10.10.10.5A full default scan of the web server on port 80.
nikto -h 10.10.10.5 -p 8080Same scan, but against a non-standard port.
nikto -h 10.10.10.5 -sslScan over HTTPS instead of plain HTTP.
Common mistakes
nikto 10.10.10.5 nikto -h 10.10.10.5
The target is never a bare argument — nikto always needs it introduced with -h.