Closed azimut closed 3 years ago
The option is to skip checking for @CGIDIRS -- which means looking for /cgi/, /cgi-bin/, etc. If none are tested, the tests with @CGIDIRS will only be checked against the root (/) of the site.
I'd be interested to hear others' thoughts on whether this should remain the behavior or actually not perform those checks. Another option might be to add a Tuning flag for anything with @CGIDIRS tests so they can be excluded that way too.
Closing due to no response.
Note: you can obtain Nikto debug output by running "-D D" and redirecting to a file
you may also scrub the output of hostnames and IPs by specifying "-D DS"
Expected behavior
Do not query for any line on databases/db_tests with
@CGIDIRS
Actual behavior
All queries are run without skipping
Steps to reproduce
./nikto.pl -Tuning 3 -Display V -port 80 -host starbucks.com.ar -Cgidirs none -Plugins "@NONE;tests"
Nikto version
Cloned from master: