Found
Duration
Date
IP
- Nikto v2.6.0
---------------------------------------------------------------------------
+ Your Nikto installation is out of date.
+ Target IP: 179.188.54.225
+ Target Hostname: tanquedigital.com.br
+ Target Port: 80
+ Platform: Linux/Unix
+ Start Time: 2026-03-28 22:52:47 (GMT-4)
---------------------------------------------------------------------------
+ Server: nginx/1.22.1
+ [999979] /: IP address found in the 'lw-x-id' header. The IP is "172.96.166.66". See: https://portswigger.net/kb/issues/00600300_private-ip-addresses-disclosed
+ [999100] /: Uncommon header(s) 'lw-x-id' found, with contents: 32780b135f2563b19a64da14534b0cb4.3504877-172.96.166.66:37582@dinesh8064.
+ No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped.
+ [95] /loja/checkout.php: Cookie PHPSESSID created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
+ [999986] /loja/checkout.php: Retrieved x-powered-by header: PHP/8.3.0.
+ [999997] /robots.txt: Entry '/loja/checkout.php' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file
+ [999997] /robots.txt: Entry '/loja/index.php' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file
+ [999997] /robots.txt: Entry '/loja/' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file
+ [999997] /robots.txt: Entry '/admin/' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file
+ [999997] /robots.txt: Entry '/loja/gerar_pix_asaas.php' is returned a non-forbidden or redirect HTTP code (200). See: https://portswigger.net/kb/issues/00600600_robots-txt-file
+ [999996] /robots.txt: contains 15 entries which should be manually viewed. See: https://developer.mozilla.org/en-US/docs/Glossary/Robots.txt
+ [013587] /: Suggested security header missing: strict-transport-security. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
+ [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
+ [600625] PHP/8.3.0 appears to be outdated (current is at least 8.5.1).
+ Scan terminated: 0 errors and 13 items reported on the remote host
+ End Time: 2026-03-28 22:53:48 (GMT-4) (61 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested
*********************************************************************
Portions of the server's headers (32780b135f2563b19a64da14534b0cb4.3504877-172.96.166.66:37582@dinesh8064) are not in
the Nikto 2.6.0 database or are newer than the known string. Would you like
to submit this information (*no server specific data*) to CIRT.net
for a Nikto update (or you may email to sullo@cirt.net) (y/n)?