Nikto is a web security and vulnerability scanner designed to detect potential security issues on web servers, including those running on Apache, IIS, and other web servers. It scans for various common web application vulnerabilities, such as cross-site scripting (XSS), SQL injection, directory traversal, and more. It also checks server configuration and can detect certain types of malware. Nikto also includes an index of known vulnerable files and programs, and can generate custom reports to help organizations keep track of their web security.
Skipfish is no longer maintained. The latest version, 2.10 beta, released in December 2012, is still available for download from Google Code Archive
By n----- · Dec 2013
Nikto es una alternativa a Nessus, pero ambas no son satisfactorias. Si bien Nessus solo le permite escanear su propia red de área local sin comprar una licencia terriblemente costosa, nikto no se mantiene actualizado. Hoy, el último registro de cambios para mí fue de 12 meses. eso no parece correcto cuando se trata de seguridad. Después de probar muchas de estas herramientas que solo hacen uso de NMAP y una fuente de CVE, considero que openVAS es la mejor opción.
Nikto is a relatively comprehensive web application scanner, SHODAN is a search engine for connected devices with open ports. They are not really that similar and their intended purpose is much more different.