[Nikto-discuss] Nikto Not Finding Webserver
maddaemon at gmail.com
maddaemon at gmail.com
Tue Jan 27 21:36:25 UTC 2009
On Wed, Jan 21, 2009 at 12:49 PM, David Lodge <dave at cirt.net> wrote:
> On Tue, 20 Jan 2009 18:41:37 -0000, maddaemon at gmail.com
> <maddaemon at gmail.com> wrote:
>>
>> I tried to update the ticket, but I can't seem to find a way to do that.
>
> You need an assembla account to update tickets, as an anonymous user you can
> only create them...
Actually, I created an account prior to reporting the bug. After I'm
logged in, there's nothing to let me update the ticket - just view.
*shrug*
>> The CHECKMETHODS=HEAD GET wasn't in the nikto.conf, so I added it and
>> launched a scan. It now appears that Nikto automatically detects the
>> redirect to SSL, and tests both port 80 as well as 443:
>
> Thought that was so; so I'm going to change the bug to mention that
> CHECKMETHODS should have a default set (probably to nikto 2.02 - which is
> HEAD). This is a lesson for me: don't change the config file without
> providing warnings or a default.
>
>> + SSL Info: Ciphers: Unknown
>> Info: Unknown
>> Subject: Unknown
>> It still isn't able to get the ciphers list, but that's another issue
>> entirely.
>
> Okay; that's interesting, I can have a look at that, but I'll need the
> results of a "-D d" to do that.
I thought I posted that earlier, but if not, I'll post it again
tomorrow when I run another scan.
> Thanks
>
> dave
>
--
<insert witty random quote here>
More information about the Nikto-discuss
mailing list