[Nikto-discuss] Nikto Not Finding Webserver

maddaemon at gmail.com maddaemon at gmail.com
Tue Jan 27 21:36:25 UTC 2009


On Wed, Jan 21, 2009 at 12:49 PM, David Lodge <dave at cirt.net> wrote:
> On Tue, 20 Jan 2009 18:41:37 -0000, maddaemon at gmail.com
> <maddaemon at gmail.com> wrote:
>>
>> I tried to update the ticket, but I can't seem to find a way to do that.
>
> You need an assembla account to update tickets, as an anonymous user you can
> only create them...

Actually, I created an account prior to reporting the bug.  After I'm
logged in, there's nothing to let me update the ticket - just view.
*shrug*

>> The CHECKMETHODS=HEAD GET wasn't in the nikto.conf, so I added it and
>> launched a scan.  It now appears that Nikto automatically detects the
>> redirect to SSL, and tests both port 80 as well as 443:
>
> Thought that was so; so I'm going to change the bug to mention that
> CHECKMETHODS should have a default set (probably to nikto 2.02 - which is
> HEAD). This is a lesson for me: don't change the config file without
> providing warnings or a default.
>
>> + SSL Info:        Ciphers: Unknown
>>                   Info:    Unknown
>>                   Subject: Unknown
>> It still isn't able to get the ciphers list, but that's another issue
>> entirely.
>
> Okay; that's interesting, I can have a look at that, but I'll need the
> results of a "-D d" to do that.

I thought I posted that earlier, but if not, I'll post it again
tomorrow when I run another scan.

> Thanks
>
> dave
>



-- 

<insert witty random quote here>


More information about the Nikto-discuss mailing list