All integrations
Nikto logo
// Tentacle Tool · DAST

Cracken + Nikto

Cracken runs Nikto against a web server to flag dangerous files, outdated software versions, and misconfigurations. It works each hit live to see which one actually lets an attacker in.

Get started
// 01

Connecting Nikto

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed on a Tentacle, then invoked during an operation (the agent can install and uninstall it mid-run)

Requires

A Tentacle running Linux — macOS is not supported, so a macOS Tentacle reports Not eligible. Free licence, nothing to purchase and no credentials to supply.

// 02

What Cracken gets from Nikto

  • Findings against a web server, classified by Nikto's own tuning categories: interesting file / seen in logs, misconfiguration / default file, information disclosure, injection (XSS/script/HTML), remote file retrieval inside web root, denial of service, remote file retrieval server-wide, command execution / remote shell, SQL injection, file upload, authentication bypass, software identification, remote source inclusion, web service, administrative console

  • Identified web server and software, fingerprinted from headers, content and file analysis

  • Hits from checks for 8,000+ potentially dangerous files and programs

  • Outdated-version findings against thousands of servers and components

  • Reports written as json, xml, htm, txt, csv or sql, several formats per scan

// 03

What Nikto does not do

Nikto identifies and reports; its tuning list names the vulnerability classes it checks for, not attacks it carries out, and the manpage describes it as a scanner performing tests for items "generally considered dangerous" rather than an exploitation tool. Cracken's nikto edition is Linux-only, so it registers as "Not eligible" on a macOS Tentacle, and the vendor states Nikto "focuses on coverage and accuracy over speed" — it is not a fast or quiet scan.

// 04

How Cracken uses Nikto

  1. 01

    Install Nikto on a Linux Tentacle

  2. 02

    Point Cracken at a web server in scope

  3. 03

    Work each finding against the live target

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Can Cracken run Nikto on macOS or Windows?

Nikto is cross-platform Perl, but Cracken packages it to run on Linux Tentacles, the Kali containers on infrastructure you control.

Is running Nikto against my server safe?

Nikto is loud in server and WAF logs but only probes for known-bad files rather than exploiting them. Cracken runs it against your scoped target from a Tentacle you control.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real Nikto context.

See how Cracken runs Nikto on a Tentacle you host, and proves what it finds end to end.