i did my first nikto scan yesterday ifound some stuff but how can i download stuff from the server?
here is my nikto result
- Server: Apache/2.2.20 (CentOS)
- Cookie PHPSESSID created without the httponly flag
- Retrieved x-powered-by header: PHP/5.3.6
- The anti-clickjacking X-Frame-Options header is not present.
- Server leaks inodes via ETags, header found with file /cgi-bin/, inode: 115023231, size: 2413, mtime: Wed Jan 26 09:44:57 2011
- No CGI Directories found (use '-C all' to force check all possible dirs)
- Apache/2.2.20 appears to be outdated (current is at least Apache/2.4.7). Apache 2.0.65 (final release) and 2.2.26 are also current.
- Web Server returns a valid response with junk HTTP methods, this may cause false positives.
- /config.php: PHP Config file may contain database IDs and passwords.
- OSVDB-12184: /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
- OSVDB-12184: /?=PHPE9568F34-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
- OSVDB-12184: /?=PHPE9568F35-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
- OSVDB-3092: /homepage/: This might be interesting...
- ERROR: Error limit (20) reached for host, giving up. Last error: opening stream: can't connect (timeout): Operation now in progress
- Scan terminated: 20 error(s) and 11 item(s) reported on remote host
- End Time: 2015-02-15 18:18:56 (GMT-5) (2023 seconds)
Comments
No Comments Exist
Be the first, drop a comment!