[Nikto-discuss] Encoding (evasion) options not visible in packet captures or server logs

Matt James mattyjimjam at gmail.com
Sat Dec 7 02:51:35 CST 2013


Hello All,

I've been testing with Nikto version 2.1.5 on Backtrack 5r3 and I can't see
the encoding options going across the wire or in the target server's logs.
 I'm assuming the Nikto testing URI are encoded by the LM2.pm module then
sent over the wire to the target?

I pulled down the current version of Nikto from the site and running it
from a Fedora system and still have the same issue.

Command: -h targetexample.com -evasion 12345678

Nikto displays the evasion options in the banner, the User Agent show which
options I'm using, but no encoding of the URI is visible in Wireshark
captures or in the target server's logs.

Everything looks in order and LW2.pm (which I take to be the worker to do
the encoding) is in the right place.

Any clues on what I'm missing?

Thanks

MattyJ
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://attrition.org/pipermail/nikto-discuss/attachments/20131207/89cca23d/attachment-0001.html>


More information about the Nikto-discuss mailing list