- Nikto v2.1.5
---------------------------------------------------------------------------
+ Target IP:Â Â Â Â Â 127.0.0.1
+ Target Hostname:Â Â localhost
+ Target Port:Â Â Â Â 80
+ Start Time:Â Â Â Â Â 2017-10-21 15:58:08 (GMT-4)
---------------------------------------------------------------------------
+ Server: Apache/2.4.16 (Unix) OpenSSL/1.0.1p PHP/5.6.12 mod_perl/2.0.8-dev Perl/v5.16.3
+ Retrieved x-powered-by header: PHP/5.6.12
+ The anti-clickjacking X-Frame-Options header is not present.
+ Server leaks inodes via ETags, header found with file /favicon.ico, fields: 0x78ae 0x4303112ee9900Â
+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
+ OSVDB-3268: /webalizer/: Directory indexing found.
+ OSVDB-3268: /img/: Directory indexing found.
+ OSVDB-3092: /img/: This might be interesting...
+ Cookie phpMyAdmin created without the httponly flag
+ Uncommon header 'x-ob_mode' found, with contents: 1
+ OSVDB-3092: /phpmyadmin/changelog.php: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
+ OSVDB-3268: /icons/: Directory indexing found.
+ Uncommon header 'x-frame-options' found, with contents: DENY
+ Uncommon header 'content-security-policy' found, with contents: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' ;;style-src 'self' 'unsafe-inline' ;img-src 'self' data:Â *.
tile.openstreetmap.org *.
tile.opencyclemap.org;
+ Uncommon header 'x-webkit-csp' found, with contents: default-src 'self' ;script-src 'self'Â 'unsafe-inline' 'unsafe-eval';style-src 'self' 'unsafe-inline' ;img-src 'self' data:Â *.
tile.openstreetmap.org *.
tile.opencyclemap.org;
+ OSVDB-6694: /.DS_Store: Apache on Mac OSX will serve the .DS_Store file, which contains sensitive information. Configure Apache to ignore this file or upgrade to a newer version.
+ OSVDB-3233: /icons/README: Apache default file found.
+ /phpmyadmin/: phpMyAdmin directory found
+ 6544 items checked: 0 error(s) and 18 item(s) reported on remote host
+ End Time:Â Â Â Â Â Â 2017-10-21 15:58:20 (GMT-4) (12 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested