Files
autorecon/results/report.md/familytree.lan.ddnsgeek.com/Services/Service - tcp-443-http/nikto.md
T
2026-04-14 17:49:38 +10:00

4.4 KiB

nikto -ask=no -Tuning=x4567890ac -nointeractive -host https://familytree.lan.ddnsgeek.com:443 2>&1 | tee "/root/results/familytree.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nikto.txt"

/root/results/familytree.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nikto.txt:

perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
	LANGUAGE = (unset),
	LC_ALL = (unset),
	LC_CTYPE = (unset),
	LC_NUMERIC = "en_AU.UTF-8",
	LC_COLLATE = (unset),
	LC_TIME = "en_AU.UTF-8",
	LC_MESSAGES = (unset),
	LC_MONETARY = "en_AU.UTF-8",
	LC_ADDRESS = "en_AU.UTF-8",
	LC_IDENTIFICATION = "en_AU.UTF-8",
	LC_MEASUREMENT = "en_AU.UTF-8",
	LC_PAPER = "en_AU.UTF-8",
	LC_TELEPHONE = "en_AU.UTF-8",
	LC_NAME = "en_AU.UTF-8",
	LANG = "en_US.UTF-8"
    are supported and installed on your system.
perl: warning: Falling back to a fallback locale ("en_US.UTF-8").
- Nikto v2.6.0
---------------------------------------------------------------------------
+ Your Nikto installation is out of date.
+ Target IP:          167.179.167.166
+ Target Hostname:    familytree.lan.ddnsgeek.com
+ Target Port:        443
---------------------------------------------------------------------------
+ SSL Info:           Subject:  /CN=familytree.lan.ddnsgeek.com
                      CN:       familytree.lan.ddnsgeek.com
                      SAN:      familytree.lan.ddnsgeek.com
                      Ciphers:  TLS_AES_128_GCM_SHA256
                      Issuer:   /C=US/O=Let's Encrypt/CN=R13
+ Platform:           Unknown
+ Start Time:         2026-04-14 03:26:38 (GMT0)
---------------------------------------------------------------------------
+ Server: gunicorn
+ [999984] /: Server may leak inodes via ETags, header found with file /, inode: 1775817020.0, size: 1497, mtime: 1563297874. See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1418
+ [999100] /: Uncommon header(s) 'content-disposition' found, with contents: inline; filename=index.html.
+ No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped.
+ [999966] /: The Content-Encoding header is set to "deflate" which may mean that the server is vulnerable to the BREACH attack. See: http://breachattack.com/
+ [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy
+ [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
+ [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy
+ [999990] OPTIONS: Allowed HTTP Methods: POST, GET, OPTIONS, HEAD .
+ [002739] /.htpasswd: Contains authorization information.
+ [002743] /.bash_history: A user's home directory may be set to the web root, the shell history was retrieved. This should not be accessible via the web.
+ [002756] /.sh_history: A user's home directory may be set to the web root, the shell history was retrieved. This should not be accessible via the web.
+ [007203] /userdata.json: This might be interesting.
+ [007204] /login.json: This might be interesting.
+ [007205] /master.json: This might be interesting.
+ [007206] /masters.json: This might be interesting.
+ [007207] /connections.json: This might be interesting.
+ [007208] /connection.json: This might be interesting.
+ [007210] /PasswordsData.json: This might be interesting.
+ [007211] /users.json: This might be interesting.
+ [007212] /conndb.json: This might be interesting.
+ [007213] /conn.json: This might be interesting.
+ [007215] /accounts.json: This might be interesting.
+ [007303] /JAMonAdmin.jsp: JAMon - Java Application Monitor Admin interface identified. Versions 2.7 and earlier contain XSS vulnerabilities. See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6235
+ [007352] /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/
+ 8627 requests: 16 errors and 23 items reported on the remote host
+ End Time:           2026-04-14 04:08:23 (GMT0) (2505 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested