~/Desktop/nikto-1.35$ perl nikto.pl -host xxxxxxxxxxxxl
-***** SSL support not available (see docs for SSL install instructions) *****
---------------------------------------------------------------------------
- Nikto 1.35/1.34 - www.cirt.net
+ Target IP: xxxxxxxxxxxx
+ Target Hostname: xxxxxxxxxxxxxx
+ Target Port: 80
+ Start Time: Wed Mar 29 00:00:30 2006
---------------------------------------------------------------------------
- Scan is dependent on "Server" string which can be faked, use -g to override
+ Server: Apache/2.0.52 (Fedora)
+ Allowed HTTP Methods: GET,HEAD,POST,OPTIONS,TRACE
+ HTTP method 'TRACE' is typically only used for debugging. It should be disabled. OSVDB-877.
+ Apache/2.0.52 appears to be outdated (current is at least Apache/2.0.54). Apache 1.3.33 is still maintained and considered secure.
+ 2.0.52 (Fedora) - TelCondex Simpleserver 2.13.31027 Build 3289 and below allow directory traversal with '/.../' entries.
+ /icons/ - Directory indexing is enabled, it should only be enabled for specific directories (if required). If indexing is not used all, the /icons directory should be removed. (GET)
+ /manual/images/ - Apache 2.0 directory indexing is enabled, it should only be enabled for specific directories (if required). Apache's manual should be removed and directory indexing disabled. (GET)
+ / - TRACE option appears to allow XSS or credential theft. See http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf for details (TRACE)
+ /images/ - index of image directory available (GET)
+ /manual/ - Web server manual? tsk tsk. (GET)
+ /webmail/ - Redirects to src/login.php , Web based mail package installed.
+ /phpmyadmin/ - This might be interesting... (GET)
+ /webmail/src/read_body.php - This might be interesting... has been seen in web logs from an unknown scanner. (GET)
+ 2563 items checked - 7 item(s) found on remote host(s)
+ End Time: Wed Mar 29 00:26:03 2006 (1533 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested
************************************
Bueno amigos eso fue un escaneo a x servidor mi pregunta es que si el sistema tiene algo peligroso segun el reporte de este escaneo alguno de ustedes que me ayude adios ...










Autor


En línea



