\documentclass[10pt,a4paper]{article} % Packages \usepackage{fancyhdr} % For header and footer \usepackage{multicol} % Allows multicols in tables \usepackage{tabularx} % Intelligent column widths \usepackage{tabulary} % Used in header and footer \usepackage{hhline} % Border under tables \usepackage{graphicx} % For images \usepackage{xcolor} % For hex colours %\usepackage[utf8x]{inputenc} % For unicode character support \usepackage[T1]{fontenc} % Without this we get weird character replacements \usepackage{colortbl} % For coloured tables \usepackage{setspace} % For line height \usepackage{lastpage} % Needed for total page number \usepackage{seqsplit} % Splits long words. %\usepackage{opensans} % Can't make this work so far. Shame. Would be lovely. \usepackage[normalem]{ulem} % For underlining links % Most of the following are not required for the majority % of cheat sheets but are needed for some symbol support. \usepackage{amsmath} % Symbols \usepackage{MnSymbol} % Symbols \usepackage{wasysym} % Symbols %\usepackage[english,german,french,spanish,italian]{babel} % Languages % Document Info \author{sinnert} \pdfinfo{ /Title (nikto.pdf) /Creator (Cheatography) /Author (sinnert) /Subject (Nikto Cheat Sheet) } % Lengths and widths \addtolength{\textwidth}{6cm} \addtolength{\textheight}{-1cm} \addtolength{\hoffset}{-3cm} \addtolength{\voffset}{-2cm} \setlength{\tabcolsep}{0.2cm} % Space between columns \setlength{\headsep}{-12pt} % Reduce space between header and content \setlength{\headheight}{85pt} % If less, LaTeX automatically increases it \renewcommand{\footrulewidth}{0pt} % Remove footer line \renewcommand{\headrulewidth}{0pt} % Remove header line \renewcommand{\seqinsert}{\ifmmode\allowbreak\else\-\fi} % Hyphens in seqsplit % This two commands together give roughly % the right line height in the tables \renewcommand{\arraystretch}{1.3} \onehalfspacing % Commands \newcommand{\SetRowColor}[1]{\noalign{\gdef\RowColorName{#1}}\rowcolor{\RowColorName}} % Shortcut for row colour \newcommand{\mymulticolumn}[3]{\multicolumn{#1}{>{\columncolor{\RowColorName}}#2}{#3}} % For coloured multi-cols \newcolumntype{x}[1]{>{\raggedright}p{#1}} % New column types for ragged-right paragraph columns \newcommand{\tn}{\tabularnewline} % Required as custom column type in use % Font and Colours \definecolor{HeadBackground}{HTML}{333333} \definecolor{FootBackground}{HTML}{666666} \definecolor{TextColor}{HTML}{333333} \definecolor{DarkBackground}{HTML}{2AA373} \definecolor{LightBackground}{HTML}{F1F9F6} \renewcommand{\familydefault}{\sfdefault} \color{TextColor} % Header and Footer \pagestyle{fancy} \fancyhead{} % Set header to blank \fancyfoot{} % Set footer to blank \fancyhead[L]{ \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{C} \SetRowColor{DarkBackground} \vspace{-7pt} {\parbox{\dimexpr\textwidth-2\fboxsep\relax}{\noindent \hspace*{-6pt}\includegraphics[width=5.8cm]{/web/www.cheatography.com/public/images/cheatography_logo.pdf}} } \end{tabulary} \columnbreak \begin{tabulary}{11cm}{L} \vspace{-2pt}\large{\bf{\textcolor{DarkBackground}{\textrm{Nikto Cheat Sheet}}}} \\ \normalsize{by \textcolor{DarkBackground}{sinnert} via \textcolor{DarkBackground}{\uline{cheatography.com/184781/cs/38587/}}} \end{tabulary} \end{multicols}} \fancyfoot[L]{ \footnotesize \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{LL} \SetRowColor{FootBackground} \mymulticolumn{2}{p{5.377cm}}{\bf\textcolor{white}{Cheatographer}} \\ \vspace{-2pt}sinnert \\ \uline{cheatography.com/sinnert} \\ \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Cheat Sheet}} \\ \vspace{-2pt}Not Yet Published.\\ Updated 15th December, 2023.\\ Page {\thepage} of \pageref{LastPage}. \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Sponsor}} \\ \SetRowColor{white} \vspace{-5pt} %\includegraphics[width=48px,height=48px]{dave.jpeg} Measure your website readability!\\ www.readability-score.com \end{tabulary} \end{multicols}} \begin{document} \raggedright \raggedcolumns % Set font size to small. Switch to any value % from this page to resize cheat sheet text: % www.emerson.emory.edu/services/latex/latex_169.html \footnotesize % Small font. \begin{multicols*}{2} \begin{tabularx}{8.4cm}{x{1.14 cm} x{5.7 cm} p{0.76 cm} } \SetRowColor{DarkBackground} \mymulticolumn{3}{x{8.4cm}}{\bf\textcolor{white}{Installation \& Getting Started}} \tn % Row 0 \SetRowColor{LightBackground} \seqsplit{Website} & \seqsplit{https://github.com/sullo/nikto.git} & \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} \seqsplit{Install} & git clone \seqsplit{https://github.com/sullo/nikto.git} & \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} Kali & apt install nikto & \tn % Row Count 5 (+ 1) \hhline{>{\arrayrulecolor{DarkBackground}}---} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{2.8 cm} x{5.2 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Commands}} \tn % Row 0 \SetRowColor{LightBackground} nikto -H, -Help & Help options \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} -ask+ & yes Ask about each (default). \{\{nl\}\} no Don't ask don't send.\{\{nl\}\} auto Don't ask, just send \tn % Row Count 6 (+ 4) % Row 2 \SetRowColor{LightBackground} -Cgidirs+ & Scan these CGI dirs: "none", "all", or values like "/cgi/ /cgi-a" \tn % Row Count 9 (+ 3) % Row 3 \SetRowColor{white} -config+ & Use this config file \tn % Row Count 10 (+ 1) % Row 4 \SetRowColor{LightBackground} -Display+ \# or letter & Turn on/off display outlets.\{\{nl\}\} 1 Show redirects. \{\{nl\}\} 3 Show all 200/OK responses \{\{nl\}\} 4 Show URLs which require authentication D Debug output \{\{nl\}\} E Display all HTTP errors \{\{nl\}\} P Print progress to STDOUT \{\{nl\}\} S Scrub output of IPs and hostnames \{\{nl\}\} V Verbose output \tn % Row Count 26 (+ 16) % Row 5 \SetRowColor{white} -dbcheck & Check database and other key files for syntax errors \tn % Row Count 28 (+ 2) % Row 6 \SetRowColor{LightBackground} -evasions+ \# or letter & 1 Random URI encoding (non-UTF8) \{\{nl\}\} 2 Directory self-reference \{\{nl\}\} 3 Premature URL ending \{\{nl\}\} 4 Prepend long random string \{\{nl\}\} 5 Fake parameter \{\{nl\}\} 6 TAB as request spacer \{\{nl\}\} 7 Change the case of the URL \{\{nl\}\} 8 Use Windows directory separator (\textbackslash{}) \{\{nl\}\} A Use a carriage return (0x0d) as a request spacer \{\{nl\}\} B Use binary value 0x0b as a request spacer \tn % Row Count 55 (+ 27) \end{tabularx} \par\addvspace{1.3em} \vfill \columnbreak \begin{tabularx}{8.4cm}{x{2.8 cm} x{5.2 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Commands (cont)}} \tn % Row 7 \SetRowColor{LightBackground} -Format+ & Save file (-o) format: \{\{nl\}\} csv Comma-separated-value \{\{nl\}\} htm HTML Format \{\{nl\}\} msf+ Log to Metasploit\{\{nl\}\} nbe Nessus NBE format \{\{nl\}\} txt Plain text \{\{nl\}\} xml XML Format \{\{nl\}\} (if not specified the format will be taken from the file extension passed to -output) \tn % Row Count 18 (+ 18) % Row 8 \SetRowColor{white} -host+ & Target host \tn % Row Count 19 (+ 1) % Row 9 \SetRowColor{LightBackground} -list-plugins & List all available plugins, perform no testing \tn % Row Count 21 (+ 2) % Row 10 \SetRowColor{white} -maxtime+ & Maximum testing time per host \tn % Row Count 23 (+ 2) % Row 11 \SetRowColor{LightBackground} \seqsplit{-mutate-options} & Provide information for mutates \tn % Row Count 25 (+ 2) % Row 12 \SetRowColor{white} -nolookup & Disables DNS lookups \tn % Row Count 26 (+ 1) % Row 13 \SetRowColor{LightBackground} -nossl & Disables the use of SSL \tn % Row Count 27 (+ 1) % Row 14 \SetRowColor{white} -no404 & Disables nikto attempting to guess a 404 page \tn % Row Count 29 (+ 2) % Row 15 \SetRowColor{LightBackground} -output+ & Write output to this file ('.' for auto-name) \tn % Row Count 31 (+ 2) \end{tabularx} \par\addvspace{1.3em} \vfill \columnbreak \begin{tabularx}{8.4cm}{x{2.8 cm} x{5.2 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Commands (cont)}} \tn % Row 16 \SetRowColor{LightBackground} -port+ & Port to use (default 80) \tn % Row Count 1 (+ 1) % Row 17 \SetRowColor{white} -root+ & Prepend root value to all requests, format is /directory \tn % Row Count 4 (+ 3) % Row 18 \SetRowColor{LightBackground} -Save & Save positive responses to this directory ('.' for auto-name) \tn % Row Count 7 (+ 3) % Row 19 \SetRowColor{white} -ssl & Force ssl mode on port \tn % Row Count 8 (+ 1) % Row 20 \SetRowColor{LightBackground} -Tuning+ \# or letter & Scan tuning: \{\{nl\}\}1 Interesting File / Seen in logs \{\{nl\}\} 2 Misconfiguration / Default File \{\{nl\}\} 3 Information Disclosure \{\{nl\}\} 4 Injection (XSS/Script/HTML) \{\{nl\}\} 5 Remote File Retrieval - Inside Web Root \{\{nl\}\} 6 Denial of Service \{\{nl\}\} 7 Remote File Retrieval - Server Wide \{\{nl\}\} 8 Command Execution / Remote Shell \{\{nl\}\} 9 SQL Injection \{\{nl\}\} 0 File Upload \{\{nl\}\} a Authentication Bypass \{\{nl\}\} b Software Identification \{\{nl\}\} c Remote Source Inclusion \{\{nl\}\} x Reverse Tuning Options (i.e., include all except specified) \tn % Row Count 46 (+ 38) \end{tabularx} \par\addvspace{1.3em} \vfill \columnbreak \begin{tabularx}{8.4cm}{x{2.8 cm} x{5.2 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{Commands (cont)}} \tn % Row 21 \SetRowColor{LightBackground} -timeout+ & Timeout for requests (default 10 seconds) \tn % Row Count 2 (+ 2) % Row 22 \SetRowColor{white} -until & Run until the specified time or duration \tn % Row Count 4 (+ 2) % Row 23 \SetRowColor{LightBackground} -vhost+ & Virtual host (for Host header) \tn % Row Count 6 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} % That's all folks \end{multicols*} \end{document}