Nikto

Classic web server vulnerability scanner.

KaliParrotLinuxhigh

pkg: nikto

Nikto checks web servers for thousands of dangerous files, outdated software and common misconfigurations.

Syntax

nikto -h {url}

Example

nikto -h https://example.com

Scans the target for known-bad files, headers and server issues.

Options & flags

What each switch does. Toggle them in the builder below to assemble a command.

-h <https://target.tld>Target host or URL.
-p <443>Port(s) to test.
-ssl <value>Force SSL/TLS.
-Tuning <1234>Limit test categories (e.g. 1=files, 9=SQLi).
-output <report.html>Write a report to a file.
-Format <htm>Report format (htm, csv, xml, txt).
-nointeractiveRun without prompts.
-useragent <Mozilla/5.0>Custom User-Agent string.

Command builder

Tick options (and fill any values) to build a ready-to-copy command.

nikto

Usage examples

nikto -h https://target.tld

Standard web server scan.

nikto -h target.tld -p 443 -ssl -output report.html -Format htm

TLS scan with an HTML report.

Advantages
  • Broad coverage of common issues
  • Zero configuration
  • Fast to run
Disadvantages
  • Extremely noisy / easily blocked
  • Many false positives
  • No app-logic testing
Tags
#web#scanner

Official docs: Nikto ↗

Related commands

Frequently asked questions

What is Nikto used for?
Nikto checks web servers for thousands of dangerous files, outdated software and common misconfigurations.
What is an example Nikto command?
A common example is: nikto -h https://example.com — Scans the target for known-bad files, headers and server issues.
Is Nikto part of Kali Linux?
Yes. Nikto ships with Kali Linux (and Parrot OS). If missing, install it with: sudo apt install nikto.
What category of security tool is Nikto?
Nikto is a Vulnerability Analysis tool with a high-risk profile when run against a live target.

Try recon tools live

Run real scans against a domain you control, stage by stage.

Open the lab →