[2026-08-25 11:12:29] Nikto 掃描開始 目標:https://is.ypu.edu.tw 額外參數: + ERROR: Host maximum execution time of 600 seconds reached + ERROR: Host maximum execution time of 600 seconds reached + ERROR: Host maximum execution time of 600 seconds reached --- Nikto 輸出 --- - Nikto v2.1.5 --------------------------------------------------------------------------- + Target IP: 120.106.194.5 + Target Hostname: is.ypu.edu.tw + Target Port: 443 --------------------------------------------------------------------------- + SSL Info: Subject: /C=TW/ST=Hsinchu/O=YuanPei University of Medical Technology/CN=*.ypu.edu.tw Ciphers: ECDHE-RSA-AES256-GCM-SHA384 Issuer: /C=GB/O=Sectigo Limited/CN=Sectigo Public Server Authentication CA OV R36 + Start Time: 2026-08-25 03:12:32 (GMT0) --------------------------------------------------------------------------- + Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips mod_fcgid/2.3.9 PHP/7.4.8 + Cookie XSRF-TOKEN created without the secure flag + Cookie XSRF-TOKEN created without the httponly flag + Cookie _session created without the secure flag + Retrieved x-powered-by header: PHP/7.4.8 + The anti-clickjacking X-Frame-Options header is not present. + Uncommon header 'strict-transport-security' found, with contents: max-age=31536000; includeSubDomains; preload + Root page / redirects to: https://is.ypu.edu.tw/login + Server leaks inodes via ETags, header found with file /robots.txt, fields: 0x18 0x5a684355b6741 + "robots.txt" retrieved but it does not contain any 'disallow' entries (which is odd). + Server is using a wildcard certificate: '*.ypu.edu.tw' + Allowed HTTP Methods: GET, HEAD + OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST + OSVDB-3092: /web.config: ASP config file is accessible. + Scan terminated: 0 error(s) and 12 item(s) reported on remote host + End Time: 2026-08-25 03:22:33 (GMT0) (601 seconds) --------------------------------------------------------------------------- + 1 host(s) tested --- [Nikto 結束] exit=0