LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-12-2006, 12:45 AM   #1
noir911
Member
 
Registered: Apr 2004
Posts: 682

Rep: Reputation: Disabled
nikto scan


I did a scan on a webserver (apache) and the only "problem" Nikto v1.34 is reporting is

/?Open - This displays a list of all databases on the server. ĘDisable this capability via server options. (GET)

I cannot make any sense of this message. The web-server is not linked to any database.

Does anyone know what this message means and how to disable it?
 
Old 03-12-2006, 05:38 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Well, two things. One way is to find out what within Nikto raised the warning (that is, based on what conditions) and assess from there if Apache config change is needed or if this is a false positive. Another way could be to have a second opinion using say a Nessus scan. If you dont run Nessus there is a free public service that does Nessus scans but I forgot the URI, shouldnt be hard to find though.

Last edited by unSpawn; 03-12-2006 at 05:39 AM.
 
Old 03-14-2006, 01:23 AM   #3
noir911
Member
 
Registered: Apr 2004
Posts: 682

Original Poster
Rep: Reputation: Disabled
Yeah, I do run nessus. Thanks for your input on assessing both the results. Appreciate it!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Nikto mutate option bertheylen Linux - Software 6 02-15-2006 07:05 AM
Nikto <GET> method noir911 Linux - Security 0 05-10-2005 08:23 AM
Nikto Scanner igor8 Linux - Security 7 06-14-2004 12:05 PM
newbie learning NMAP, NESSUS, NIKTO amrogers3 Linux - Newbie 1 01-28-2004 03:55 PM
Nikto: Security Scanner Par4n0iA Linux - Security 1 08-05-2003 02:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration