The HTML & XML report templates and nikto.dtd are missing from the nikto package.
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
nikto (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: nikto
Ubuntu release information:
$ lsb_release -rd
Description: Ubuntu 9.04
Release: 9.04
Package name and version:
$ aptitude show nikto | egrep 'Package|Version'
Package: nikto
Version: 2.03-1
Description of problem:
The HTML & XML report templates and nikto.dtd are missing from the nikto package.
Search for the templates folder and nikto.dtd:
$ dpkg -L nikto | egrep 'templates|
Nikto generated errors when using HTML report format:
$ nikto -h 127.0.0.1 -p 80 -F html -o 127.0.0.1_80.html
+ ERROR: Can't open directory '/var/lib/
Nikto generated errors when using the XML report format:
$ nikto -h 127.0.0.1 -p 80 -F xml -o 127.0.0.1_80.xml
+ ERROR: reading DTD
+ ERROR: reading DTD
Nikto config.txt reference to nikto.dtd:
$ egrep nikto.dtd /etc/nikto/
NIKTODTD=
Potential resolution:
Update the package by adding the templates folder to "/var/lib/nikto/". Then add "nikto.dtd" to "/usr/share/
Bug exists in 10.04
$ dpkg -s nikto config. txt a7aaa7c777710d1 220a55b386078a8 08 Maintainer: Vincent Bernat <email address hidden> cirt.net/ nikto2
Package: nikto
Status: install ok installed
Priority: extra
Section: non-free/net
Installed-Size: 1132
Maintainer: Ubuntu Developers <email address hidden>
Architecture: all
Version: 2.03-2
Depends: perl, libwhisker2-perl, libnet-ssleay-perl
Suggests: nmap
Conffiles:
/etc/nikto/
Description: web server security scanner
Nikto is a pluggable web server and CGI scanner written in Perl, using
rfp's LibWhisker to perform fast security or informational checks.
.
Features:
- Easily updatable CSV-format checks database
- Output reports in plain text or HTML
- Available HTTP versions automatic switching
- Generic as well as specific server software checks
- SSL support (through libnet-ssleay-perl)
- Proxy support (with authentication)
- Cookies support
Original-
Homepage: http://
$ cat /etc/lsb-release RELEASE= 10.04 CODENAME= lucid DESCRIPTION= "Ubuntu 10.04.4 LTS"
DISTRIB_ID=Ubuntu
DISTRIB_
DISTRIB_
DISTRIB_