Skip to content

Recommendations ​

A recommendation is a proposed follow-up action, or a piece of advice, that a scan derived from what it actually saw on the target. It is not a finding.

FindingRecommendation
Answers"here is evidence of an issue""here is something you might do next"
Lives inFindings, the reportRecommendations
Scopeone scanthe host, across every scan of it

Where to open it ​

  • Project sidebar → Recommendations — every recommendation across every host in the project (scope every host in this project). Each row shows the host URL; clicking it opens that host's own list.
  • Host → Recommendations tab — that host only (scope this host only).

Rows are per host, not per scan: a later scan that still sees the same condition bumps the existing row rather than adding a second one.

How they are produced ​

Recommendations come from Nikto and Crawl results the scan already collected — nothing extra is sent to the target to produce one. Cloud-storage listings are the main example that can be acted on from the UI; see Cloud Storage Listings.

Some rows are advice with no tool behind them. An HTTP authentication realm seen on a 401 raises one such row — a credential attack against that realm, proposed and left to you. It is manual on purpose: a full wordlist against a login is noisy and can trigger account lockout, and Nikto has already tried its default credentials during the scan. See Findings → HTTP authentication realms.

Each row carries:

FieldWhat it means
RuleWhich check produced the row (for example a cloud-storage listing export).
Proposed ActionThe tool the rule proposes and the URL it would be pointed at. Advisory — no automated action means the rule has no tool: it is text-only guidance.
TierAuto-safe or Manual only. Today every recommendation needs an explicit click; nothing runs on its own, whatever the tier says.
EvidenceA short snippet from when the recommendation was raised. Missing evidence shows an em dash, not an empty box. JWT rows include where the token was seen, the decoded header and payload, and the compact token — see JWT module.
StatusProposed (the default), Dismissed, or Executed.
Seen N×How many times this exact condition has been observed, plus the time it was last seen.

The same condition on the same host stays one row and bumps Seen N×. The list will not grow without bound if a page keeps repeating the same hints.

Actions ​

ActionWhat it does
Dismiss / UndismissMarks the row handled. A later scan that sees the same condition updates the count but does not undo your decision. Unavailable while an export for that row is queued or running — cancel the export first.
Delete (×)Removes the row. A later scan that sees the same condition can create it again. Unavailable while an export is queued or running — cancel the export first.
Delete allClears every recommendation on this list (the project page, or this host). Confirmation: Delete all N recommendations for this project? / …for this host? A later scan that still sees the same condition can raise the row again, but dismissals are lost. Recommendations with a job in progress are kept; the page reports Deleted N recommendations. M kept because a job is in progress — cancel the job to remove it.
Export full file listStarts a background export. Appears only on cloud-storage listing recommendations (row title Cloud Storage: Export full file list). The row shows progress and Cancel; when it finishes, Download and Re-run.
RunWorks on MS10-070 rows: it launches a Nikto scan that confirms the padding oracle on that target, behind a confirmation dialog, and links to the new scan. Disabled on every other recommendation — those rows are advice only.

Running an MS10-070 confirmation ​

Run on an MS10-070 recommendation starts a fresh scan with the MS10-070 module and Active Confirm / Exploit enabled. It reuses the originating scan's target, project, enforced proxy and headers, and throttle — the licence and scope checks apply as they do to any scan you launch yourself — and it is seeded with the candidate handler URL rather than repeating a full Nikto run.

Active confirmation sends thousands of extra requests to the target; the dialog says so before anything is launched. The row becomes Executed when the scan starts, not when it finishes — follow the link to see the result. See MS10-070.

Export full file list ​

The export walks every page of a public cloud-storage listing and stores the whole object list on the server for you to download. See Cloud Storage Listings for how those listings are detected in the first place.

Start an export ​

Click Export full file list. That does not download anything. It starts an export run: a background job the server owns. A valid license is required — this is new work against the target. Nothing opens in a new tab, and the walk does not belong to your browser session — you can navigate away, close the tab, or log back in later, and the finished file is waiting on the recommendation row.

The row itself shows the run:

Row showsMeaning
Queued…Accepted, waiting for a runner. Cancel is offered.
Walking page 312 · 311,000 files · 1.2 GBThe walk is in progress; the numbers advance about every 2 seconds. Cancel is offered.
Canceling…You clicked Cancel. A running cancel finishes within one listing page. If nothing answers for about 20 seconds, the label becomes Canceling… (no response from the export process; this resolves automatically within a minute) — usually after an API restart.
Ready · 48 MB · 3,100,000 files confirmed · 62 pages · 62 chaptersFinished. Download saves the stored file; Re-run walks the listing again. After you download it, the row also shows a muted downloaded <time>.
Failed at page N: <reason>The walk stopped. No file is stored. Re-run is offered.
Canceled · partial file · <size> · N files from N pagesYou stopped it after it had produced output. The partial file is kept: Download partial and Re-run are offered.
CanceledYou stopped it before it produced anything. No file is stored. Re-run is offered.

While any row on the page is queued or running, the list refreshes itself every 2 seconds and stops when nothing is active.

Active runs also appear on the Active Jobs page under Exports, with the recommendation, the target, the same progress, and a Cancel button — and they are counted in the sidebar's jobs badge, so a running export is visible from anywhere in the app.

Every listing page fetched is recorded in that scan's Logs, and the run uses the same throttle settings as the scan. On a clean finish the recommendation status becomes Executed.

Cancel ​

Cancel stops a queued run immediately and a running one within one listing page. What was already walked is kept: the run finishes off the file it had started and stores it as a partial export, so a cancel at page 2,000 of a three-million-key bucket does not throw those 2,000 pages away.

A partial can never pass itself off as complete. It is always a zip, it is named <bucket>-files-partial.zip, it contains an ERROR.txt naming the page the walk stopped at and why, its index.html carries an INCOMPLETE banner, and the row and the download button both say partial. It is a snapshot of what was walked, not the bucket.

A cancel that lands before the walk produced any output at all stores no file — there is nothing to keep — and the row reads as a plain Canceled.

Canceling does not mark the recommendation Executed and does not replace an earlier completed export. Re-run starts over from page 1.

Output ​

WalkOutput
Finished cleanly, under 50,000 filesA single <bucket>-files.html with one link per object.
Finished cleanly, 50,000 files or moreA <bucket>-files.zip containing files-0001.html, files-0002.html, … (50,000 links each) plus an index.html listing every chapter.
Canceled after output had startedA partial <bucket>-files-partial.zip: the chapters walked so far, an ERROR.txt saying where it stopped, and an index.html with an INCOMPLETE banner.
Canceled before any outputNothing to download.
FailedNothing to download. The run keeps the reason, not a file. A failure is not something you chose, and the reason is the deliverable.

HTML files (single page or zip chapters) open with a Nikto Platform banner — inline CSS and text, no external fonts or images.

The export uses the same listing URL the scan found (same folder/prefix on S3, same Azure container listing). It always starts from the first page.

A walk that fails part-way is reported on the row as Failed at page N with the reason (the page URL and what went wrong), and stores no file. That includes a listing page cut off by the response size limit — the reason says the file list is INCOMPLETE, and there is still no download. The export never hands you a partial list that could be mistaken for a complete one — a canceled run's partial is kept, but it is labeled as partial in its filename, its response header, its own index.html, and on the row.

Re-run and retention ​

Each recommendation keeps one stored export. When a re-run finishes, it replaces the previous file. There is no version history — download the file you need before re-running.

A finished export is kept for 7 days from when it completed. Failed and canceled runs (including partial files) are removed after one day — download a partial the same day you make it. Deleting the recommendation removes its files immediately. The row then offers Export full file list again.

One export at a time

Clicking Export full file list again while a run for that recommendation is already queued or running is refused. Cancel the run first if you want to start over.

If the export is refused ​

MessageWhat to do
The originating scan was deletedRe-scan the host so the export has a target to use.
The stored listing URL is not usableDelete the row and re-scan.
Stopped at page 1The listing could not be fetched (bucket closed, or an error page instead of a listing). Re-scan the host.
The scan's proxy no longer existsRestore the proxy under Settings, or re-scan through a live one.
The project's enforced proxy no longer existsRestore it under Settings. The export will not send traffic unproxied.
The API restarted during the exportClick Re-run.

An export also stops if it hits a time limit (default one hour) or a very large key count. The run fails with a message saying so — it does not save a truncated file that looks complete.

Proprietary software. Licensed for use under the End User License Agreement.