Scan for Vulnerabilities on Any Website Using Nikto [Tutorial]

Поділитися
Вставка
  • Опубліковано 14 чер 2024
  • Get Our Premium Ethical Hacking Bundle (90% Off): nulb.app/cwlshop
    How to Scan Websites for Vulnerabilities with Nikto
    Full Tutorial: bit.ly/NiktoScan
    Subscribe to Null Byte: goo.gl/J6wEnH
    Kody's Twitter: / kodykinzie
    Not all websites are developed the same, and a lack of security measures is all the opening a hacker needs to wreak some havoc. In this episode of Cyber Weapons Lab, we'll show you how to scan websites for vulnerabilities with Nikto, a powerful but simple tool that can perform scans on SSL/HTTPS websites, an IP address for a service on a local network, or an older HTTP web domain.
    Follow Null Byte on:
    Twitter: / nullbytewht
    Flipboard: flip.it/3.Gf_0
    Weekly newsletter: eepurl.com/dE3Ovb
  • Навчання та стиль

КОМЕНТАРІ • 346

  • @elikirkwood4580
    @elikirkwood4580 5 років тому +880

    Remember kiddies, don't try this at home. Go to a friend's house

    • @raymondy6302
      @raymondy6302 5 років тому +21

      Eli Kirkwood or use a vpn

    • @busyhacker8129
      @busyhacker8129 5 років тому +27

      Or you can you both Tor and vpn for 99% security.

    • @busyhacker8129
      @busyhacker8129 5 років тому +7

      @Islaminame
      Well ,in case of mobile phones if you try to use 2 vpns +Tor then your battery will decrease in huge amount like water from glass( if glass bends) because vpn's uses much battery as compared to Tor.

    • @mrabdego
      @mrabdego 4 роки тому +3

      hhhhhhhh

    • @sweetimpala
      @sweetimpala 4 роки тому +7

      whys that? what are the possible risk doing this at home?

  • @misterx8014
    @misterx8014 4 роки тому +166

    Moral of this video: Never ever blink when u're explaining something to someone..

  • @rickmonarch4552
    @rickmonarch4552 4 роки тому +125

    At 1:52 HE ALMOST BLINKED :OOOOOOO!!!4

    • @onions5113
      @onions5113 4 роки тому +1

      what do you mean blink i only seen that comment blink blink blink!!

    • @vladobjelis223
      @vladobjelis223 3 роки тому

      AHHAHAHAHAHAHAHAHAHAHAHHAHAHAHA good one!

  • @paprika5487
    @paprika5487 5 років тому +28

    I would love to see a part 2 of this in which you actually do pair the nikto output with some metasploit exploit. I find interpreting nikto output to be very, very difficult in relation to next steps.

    • @swine13
      @swine13 3 роки тому +2

      Right? I feel like i need a tutorial about how to make sense of the various outputs you can get

  • @ericcolt8078
    @ericcolt8078 4 роки тому +2

    Thanks Null Byte ! what would you personally recommend if you compare Burp suite vs Nikto ? for reconning and excuting and even saving databases on your targets ?

  • @galihpa
    @galihpa 5 років тому +82

    Sir next time you record a terminal window, please remember to increase the font size so that we can see the text clearly

    • @dareknaszlaku
      @dareknaszlaku 4 роки тому +1

      Indonesia switch to 720p or 1080p.

    • @IgorogI1000
      @IgorogI1000 4 роки тому +4

      i had to use the system magnifier and a real one to be able to read

    • @Crazy--Clown
      @Crazy--Clown 4 роки тому

      Use a magnifying glass

    • @nobeltnium
      @nobeltnium 3 роки тому

      I had to use a microscope

    • @rifqioktario5546
      @rifqioktario5546 3 роки тому

      Ah masa gakeliatan

  • @mrsmith4534
    @mrsmith4534 5 років тому +17

    Yes, finally we get to see u again

  • @dacman61
    @dacman61 4 роки тому +21

    Excellent video! Thank you for walking us through this process with great, efficient tips along the way. Very helpful.

  • @Dave-kq7gv
    @Dave-kq7gv 5 років тому +48

    cool content as always, man! Would it be possible for you to ctrl-shift-+ your terminal windows? Some of the smaller text doesn't render well after youtube's processing/compression/whatever

    • @NullByteWHT
      @NullByteWHT  5 років тому +20

      We'll make it bigger in future episodes

    • @MartianMoon
      @MartianMoon 5 років тому +3

      Null Byte thank you!

    • @mohsintahir8906
      @mohsintahir8906 3 роки тому

      what type of terminal u r talking about is this linux i use ctrl + alt + t

    • @user-rv5qf1ud6j
      @user-rv5qf1ud6j 3 роки тому

      @@mohsintahir8906 ctrl-shift-+ increases the text size *while* in the terminal

  • @thomasle8317
    @thomasle8317 Рік тому +1

    You can zoom screen when you type command line, it truly useful for us to following.

  • @theopposition173
    @theopposition173 4 роки тому +4

    That electric sound effect at the end of the video - you got me. I even felt the vibration coming from my laptop. Fuck sake.

  • @generalregistry
    @generalregistry 4 роки тому

    Just wanted to say thank you for your channel 👍I appreciate your presentations

  • @saiddope2241
    @saiddope2241 7 місяців тому +1

    This channel is a gem

  • @5thfloor584
    @5thfloor584 3 роки тому +7

    @15:20 thanks bro for telling me that at the very end, I thought Nikto was practically the same as nmap, so I ran it without a vpn.

    • @fritzz1593
      @fritzz1593 2 роки тому +1

      Thanks bro for telling me

  • @Uneke
    @Uneke 5 років тому

    Ever thought of following up this video with an msf meterpreter video?
    You should definitely delve into it!

  • @kfp1200
    @kfp1200 4 роки тому +54

    This dude is actually staring at my soul in every video 🥴

    • @sluvvr
      @sluvvr 3 роки тому

      Y e a h 😶

    • @djparty95
      @djparty95 2 роки тому +1

      Be careful! Staring in your history my be worse.

    • @abhishekpatil5768
      @abhishekpatil5768 Рік тому

      @@djparty95 🤣🤣

  • @poms3559
    @poms3559 5 років тому +8

    One of the first viewers. Yesss!!!

  • @Niteshshaw2011
    @Niteshshaw2011 4 роки тому +1

    I love you videos. ♥️
    Terminal Tex in this video is very small. Plz increase the font size next time. Great work guys 👍👍👍👌👌👌

  • @falcon_95
    @falcon_95 3 роки тому +1

    Hey really nice !
    Do you know how to bypass firewalls ? For some reason, -sS flag doesnt work when the network is set up with firewall or antivirus

  • @h4ckni0r38
    @h4ckni0r38 5 років тому

    Hey, Whats Up Kody, I Saw U I Kak5 Five And Wanted To Say, You Have Done A Very Good Job With This Channel

  • @mavericks.9638
    @mavericks.9638 3 роки тому +1

    sir @Null Byte do you hack with your mac OS terminal or use a VM?

  • @tota_trader
    @tota_trader 3 місяці тому

    very nicely explained. Thanks

  • @stevenlewin4129
    @stevenlewin4129 2 роки тому +2

    Why hasn't this guy got a million subs he is way better then David bombal and network chuck

  • @ProfoundKnowledge
    @ProfoundKnowledge 10 місяців тому

    May I ask what OS u are using that is best suited for cybersecurity activities 'cause I intend to buy a new one

  • @theitguy3096
    @theitguy3096 3 роки тому +5

    Just a friendly feedback: you may magnify the terminals, especially when typing the commands when the terminal is cleared and empty, e.g. @ 9:23. The clip looks like a blank screen with some little ascii on the top! :)

  • @johnvsf
    @johnvsf Рік тому

    Great video! Thank you for sharing!

  • @dareknaszlaku
    @dareknaszlaku 4 роки тому

    Have you done any Maltego episode? I just found most of it is America „focused” .

  • @un4v5s83
    @un4v5s83 3 місяці тому

    thank you very much for the nikto tutorial man

  • @Blacknova147
    @Blacknova147 3 роки тому

    When I try to output the log to metasploit using '-Format msf+' kali linux spits back an error saying it's an invalid output format

  • @angryoldcanadian3905
    @angryoldcanadian3905 5 років тому +3

    we need tutorials on Klatu and verata next

  • @mohsintahir8906
    @mohsintahir8906 3 роки тому

    i like that sepread this just for knowledge purpose

  • @vikrambc6906
    @vikrambc6906 5 років тому +1

    Hello, please provide a session on doing external pen test against public IP

  • @noelremasu
    @noelremasu Рік тому

    Great tutorial.. in your next videos please zoom in or increase the fonts of your terminal for better visibility

  • @Laflamablanca969
    @Laflamablanca969 4 роки тому +1

    Awesome vid. I don’t think you blinked the entire time 😂👍

    • @cry6270
      @cry6270 4 роки тому

      maybe he is reading what to say in the camera :)

  • @mohsintahir8906
    @mohsintahir8906 3 роки тому

    i am using unity tweak tool i can just switch on windows only like in one window i can watch a video and it is playing but on the other i open a text based app or terminal etc how i can write there i am unable to write i want to use both what i do?

  • @thuggy67
    @thuggy67 4 роки тому

    I might be slow or blind but where did you scan for vulnerability eg. website.com ?

  • @bootlegronin5082
    @bootlegronin5082 3 роки тому

    NullByte how do I pair it with the exploit since msf+ isn't an option on my kali machine running kali 2020

  • @Virlo
    @Virlo 5 років тому +1

    How do you hack a phone only with the phone number, how can you listen to people calls with a program and see where they are exactly. I saw that they can find you, and listen to you through your phone, even when your phone is offline etc. How?

  • @McnightStricker
    @McnightStricker 5 років тому

    thank you man this was good

  • @kearala7
    @kearala7 4 роки тому

    I found sql vuulnerabilty ,,will you help me in, how to search for suitable metasploit exploit for that..

  • @minigeos
    @minigeos 9 місяців тому

    very well explained

  • @SatyamWakchaure
    @SatyamWakchaure Рік тому

    Your videos are great, really really helpful 👍🏻
    But why don’t you make the font bigger ??
    Please we need that.

  • @kiranrandhawa4709
    @kiranrandhawa4709 3 роки тому

    @1:45 Altego?! Baltego?! What's the tool? Trying to scan our API to find out if there are any vulnerabilities.

  • @timothyschuebel5367
    @timothyschuebel5367 5 років тому +1

    Thanks!

  • @endless2333
    @endless2333 2 роки тому +1

    Nice class about active scan in websites. But what you've said about using a vpn or thor cause of the "suspicious" behaviour with these tools gave me a doubt.
    I'm participating some bugbounty programs, and will only use this tool in authorized scopes of programs. Do you think is needed to use a vpn to hide my ip adress? What do you think about this? Thanks for the knowledge!

    • @bazookie7577
      @bazookie7577 2 роки тому

      Tbh I would use a VPN or proxies no matter WHAT. I wouldn't risk it

  • @scarytruths01
    @scarytruths01 Рік тому

    Hm.. I have nord vpn but for some reason every time I log into it my internet doesn't work so iv been using mainly proxychains as a backup.

  • @fudoshin2776
    @fudoshin2776 3 роки тому

    I done this using a VPN and used my Linux server on Hyper V manager! Love your videos!!!

    • @mohsintahir8906
      @mohsintahir8906 3 роки тому

      is there any free vpn and best?

    • @fudoshin2776
      @fudoshin2776 3 роки тому

      new era 2017 most free VPNS are not premium and pretty shit. I would recommend paying for one or just using a free trial

    • @mohsintahir8906
      @mohsintahir8906 3 роки тому

      @@fudoshin2776 gud suggestion is there any trail bases for a long period supported 3 to 4 months

    • @fudoshin2776
      @fudoshin2776 3 роки тому

      new era 2017 no I don’t think so ( very unlikely) Different VPN providers have different time period free trials, some 7 days, 3 days, 1 month etc

    • @mohsintahir8906
      @mohsintahir8906 3 роки тому

      @@fudoshin2776 nice

  • @dukewilson1970
    @dukewilson1970 5 років тому

    Please kindly make a video series on shodan @Null Byte

  • @mohsintahir8906
    @mohsintahir8906 3 роки тому

    10:35 u r using mac ? what is best for other intel pcs

  • @philipsuser6203
    @philipsuser6203 Рік тому +1

    Are we blinking at the same time? Or he won't blinking

  • @alphacentauri8035
    @alphacentauri8035 5 років тому

    Great vid
    Whats the intro music?

  • @mocheford
    @mocheford 5 років тому +3

    thanks again, sempai

  • @mohsintahir8906
    @mohsintahir8906 3 роки тому

    can u tell me which linux u r using what type of linux system is best for find secure web kali , ubuntu or mac many people confusion on this i like ubuntu bcz its interface is beautiful but most ceh use kali or some red hat(tell me about your suggestions)

    • @alephanull1953
      @alephanull1953 3 роки тому

      Kali linux or Parrot Security OS, you CAN use Ubuntu but Mali Linux has the tools you need to hack.

  • @sasukeuchiha-gs7hd
    @sasukeuchiha-gs7hd 5 років тому

    Hi i did like the video but i had to stop it hundred of times cuz of the texts they are too small thx

  • @sonofarabia3640
    @sonofarabia3640 5 років тому +14

    Fun fact.
    Saying nikto to Saudi. Can lead to injuries.
    Lol

    • @KINGCASH1337
      @KINGCASH1337 5 років тому +4

      Nikto means fucked him

    • @slaffkas
      @slaffkas 4 роки тому +1

      Nikto means "nobody" in Russian.

  • @netbin
    @netbin 5 років тому

    hey null byte is there a way to run this scan way more faster? its taking such insane amount of time to finish it.

    • @DoorThief
      @DoorThief 5 років тому

      I'm sure there are filtering options that will speed it up. Also limiting the IP range.

  • @paulmorrey733
    @paulmorrey733 5 років тому

    Thanks

  • @francescopresta9570
    @francescopresta9570 5 років тому

    Very good job

  • @jeffpoague9831
    @jeffpoague9831 3 роки тому

    Thanks for the info man!! No puns here.

  • @jr8gong
    @jr8gong 4 роки тому +7

    good stuff but you need a magnifying glass to see the commands

    • @mohsintahir8906
      @mohsintahir8906 3 роки тому

      hahaaha he safe his site they just tell how its work

  • @jraymundotunortiz9138
    @jraymundotunortiz9138 3 роки тому

    How I can write the stray up lines in the terminal? | awk '/Up$/{print $2}' |

  • @youbeenkumjarjaron
    @youbeenkumjarjaron 4 місяці тому

    very good video

  • @harrydamour7564
    @harrydamour7564 5 років тому +2

    My friend 🙋‍♂️

  • @blakebarbee7224
    @blakebarbee7224 4 роки тому

    Oh wow this is so cool.

  • @bornabujanic7575
    @bornabujanic7575 5 років тому +1

    Hi again!

  • @TheOmarBH
    @TheOmarBH 5 років тому

    It works on WAN?

  • @aakankinskywalker384
    @aakankinskywalker384 3 місяці тому +1

    well the website I was trying to do sql attack on blocked my IP 😅

  • @afzalthaivalikakkath4263
    @afzalthaivalikakkath4263 4 роки тому

    Hai, bud
    Do one carding vedio and tools used

  • @shadowsblack3896
    @shadowsblack3896 5 років тому

    Muy pequeño lo que se escribe en la terminal. No se alcanza a ver bien.

  • @folgendhego7916
    @folgendhego7916 4 роки тому

    the best BLINK all the time 1:82

  • @maryamfarnegin1647
    @maryamfarnegin1647 2 роки тому

    thanks a lot

  • @mocheford
    @mocheford 5 років тому

    nikto -h [Domain] -Format msf+ gives me a "+error : Invalid output format" which is lame because I'd like to link it to Metasploit..

    • @mocheford
      @mocheford 5 років тому +1

      @Joey Ds LOL nope, in my Kali linux.

  • @luckycomputers4273
    @luckycomputers4273 4 роки тому +1

    not visible clearly, too small display

  • @habibizerak9567
    @habibizerak9567 5 років тому

    i have send u in twitter messege but u didnt answer, i want to talk with u pls

  • @goodtallvideo4017
    @goodtallvideo4017 5 років тому

    your the best man

  • @PhotohackLovers
    @PhotohackLovers 2 роки тому

    null byte never blinks, I'm hear for it.

  • @xbloodymatter9654
    @xbloodymatter9654 5 років тому

    I have a question, can you somehow break the secure desktop security in windows? In such a way that, for example, a keylogger process would work in order to intercept the password from uac prompt.

  • @bennypablodre7977
    @bennypablodre7977 3 роки тому

    I need to learn 😩

  • @q8tech108
    @q8tech108 3 роки тому

    I want read results idk where and how

  • @nanayawoffeiafari9768
    @nanayawoffeiafari9768 2 роки тому

    Excellent procedure but text are too small and not making the video interesting. Can you increase the text size a bit?

  • @mserwa
    @mserwa 5 років тому

    zwiększ czcionkę. Na telefonie prz 720 nic nie widać

  • @ruinedeco3526
    @ruinedeco3526 4 роки тому +1

    Tells me I shouldn’t do it on my ip at the end of the video after I’ve already done it 😂😂💀

    • @NullByteWHT
      @NullByteWHT  4 роки тому +3

      Oooppss

    • @quasa0
      @quasa0 4 роки тому

      @@NullByteWHT ahahahahahahahha

    • @quasa0
      @quasa0 4 роки тому

      @@NullByteWHT literally the same, but started trying it on my own websites ;P

  • @dolakt62
    @dolakt62 3 роки тому

    How can i bypass an admin login page using kali linux

  • @ganeshcilpa8214
    @ganeshcilpa8214 4 роки тому

    whats the cmd for windows to install

  • @SayantanHack
    @SayantanHack 4 роки тому

    Please increase the terminal font

  • @maxpowers4762
    @maxpowers4762 4 роки тому

    WTF are those straight lines in the command for saving the nullbyte.txt file to targetip.txt? i don't have such characters on my keyboard. And where and how does this command work? I just wasted an hour of my life trying to figure out this command.

  • @wishIKnewHowToLove
    @wishIKnewHowToLove 10 місяців тому

    15:13 wait how could i possibly do this in tor?

  • @dusantoda
    @dusantoda 3 роки тому

    Is it illegal to run nikto on websites?

  • @ajcarlo9992
    @ajcarlo9992 3 роки тому

    u look like Jake Gyllenhaal in the nightcrawler movie, and bobby fischer all in one

  • @1980cantrell
    @1980cantrell 5 років тому +4

    I love nikto. I incorporated it into a tool I wrote in python. 😁.
    Great video , once again.😎😎

    • @mentix002
      @mentix002 5 років тому +1

      Tool*. And making a system command via a Python script isn't really something to be proud of.

    • @netbin
      @netbin 5 років тому

      Can you show me some examples of your incorporation please?

    • @0dyss3us51
      @0dyss3us51 5 років тому +7

      @@mentix002 auch way to stifle people growth and curiosity. What a role model.

    • @NullByteWHT
      @NullByteWHT  5 років тому +6

      @Manan Yadav Why are you like this.

    • @1980cantrell
      @1980cantrell 5 років тому +1

      @@netbin build your tools and call nikto to scan for vulnerabilities. If any found than call to search for exploits if there are any than build your app/tool to execute payload.
      I can't give u an example here too much to write but if u search how to call nmap or nikto to use in python script it will show u how to call other tools to use in ur app..

  • @lawmasud1651
    @lawmasud1651 3 роки тому

    Nice

  • @arafangbarrow8517
    @arafangbarrow8517 5 років тому

    I am New here cool 😎 place to learn! How can one contact you please?

  • @dervxerox
    @dervxerox 8 місяців тому +1

    "Now, before you start running Nikto on every site you can think of.." You should have put that warning near the beginning. 😅😅

  • @barkieboys646
    @barkieboys646 5 років тому

    What do you suggest me to do get an alfa adapter or an wifi pineapple nano?

    • @Lolzzn12
      @Lolzzn12 5 років тому

      those are two completely separate things, the amount of script kiddies these videos attract is wild.

    • @barkieboys646
      @barkieboys646 5 років тому

      Lolzzn12 Please don’t react when you have no knowledge ...

    • @barkieboys646
      @barkieboys646 5 років тому

      Both are capable of monitor mode and package injection , both are able to start an evil twin attack , both can deauthenticate networks , but the pineapple nano got a better UI and is able to run many modules when the rogue acces point is online. It also has a better range. The only thing that stops me from buying the nano is money ...

  • @kivisaur
    @kivisaur 4 роки тому

    How to scan .bazar domain?

  • @kalpeshbagul3375
    @kalpeshbagul3375 4 роки тому

    Hi sir
    Please tell me
    How to hack or edit games like a free fire,pubg,mpl,etc
    With the help of html language & server side scripting & client side scripting
    Please answer me sir please...

  • @JonMartins
    @JonMartins 3 роки тому

    Is that actually a macbook or a dell with hackintosh or virtual machine?

  • @yareyaredacat9943
    @yareyaredacat9943 3 роки тому +3

    $1000 to anyone who can beat him in a staring contest

  • @SuperChelseaSW6
    @SuperChelseaSW6 5 років тому

    How do we recover the logs in a machine if an intruder wipes all the logs?

    • @DoorThief
      @DoorThief 5 років тому

      Depends on how these "logs" we're wiped. If they were simply deleted and not overwritten, data recovery tools may help you.

  • @rchilro
    @rchilro 5 років тому +3

    Use bigger fonts!!!