Appearance
Remote Access
Use the console from another computer through an SSH tunnel. Do not open it to the network.
Do not expose Nikto Platform to the internet or untrusted networks
Nikto Platform is beta software. Do not expose it to the internet or to any network you do not trust, even with operator login enabled. Beta software has not had the hardening a public-facing service needs. It is also a scanner: whoever can use it can send traffic from your machine and read everything it has found.
The console now requires a username and password before it shows any project data, but that is not a substitute for keeping it off untrusted networks — there is one account, no per-project access control, and a local attacker who reaches the sign-in screen can still lock it out (see Locked out? for signing in from the host anyway).
If AUTH=off is set in .env, there is no login at all, and anyone who can reach the console has full control:
- Run scans from your machine against any target
- Read every finding, and the credentials and headers stored with scans
- Change settings, including proxies and project settings
Default setup
The console is published on 127.0.0.1 port 3001 only (UI_PORT in .env). Only the machine that runs Docker can open it. Other machines on the network cannot connect, and no other part of the stack publishes a port.
If you changed UI_PORT, use your port wherever this page says 3001.
Use an SSH tunnel
An SSH tunnel forwards a port on your own computer to the console's loopback address on the scanner host. The console stays private, and SSH handles authentication and encryption.
On your own computer, run:
bashssh -N -L 3001:127.0.0.1:3001 user@scanner-hostReplace
user@scanner-hostwith your SSH login for the machine that runs Nikto Platform.Leave that command running.
-Ntells SSH to forward the port without opening a remote shell, so the terminal appears to hang. That is expected.Open
http://localhost:3001in a browser on your own computer.Press
Ctrl+Cin the terminal to close the tunnel when you are done.
The first 3001 is the port on your computer. Change it if that port is in use:
bash
ssh -N -L 8443:127.0.0.1:3001 user@scanner-hostThen open http://localhost:8443. The 127.0.0.1:3001 part stays the same, because it is the console's address on the scanner host.
Windows
- PowerShell: Windows 10 and later include the OpenSSH client. The
sshcommand above works the same way. - PuTTY: under Connection → SSH → Tunnels, set Source port to
3001and Destination to127.0.0.1:3001, click Add, then open the session. Browse tohttp://localhost:3001while the session is open.
Keep the tunnel open
ssh -f -N -L 3001:127.0.0.1:3001 user@scanner-hostsends the tunnel to the background after you log in. Stop it by ending thatsshprocess.autossh, where installed, restarts the tunnel if the connection drops.
Other private options
A VPN or overlay network you already trust, such as WireGuard or Tailscale, can carry the SSH tunnel. Keep the console on 127.0.0.1 and run the tunnel over that network. The VPN limits who can reach the host; it does not add a login to the console.
What not to do
- Do not change the port binding. Leave
127.0.0.1:in front of the console port in the compose file. Changing it to0.0.0.0, or removing it, opens the console to every network the host is on. - Do not put the console behind a public reverse proxy, and do not port-forward it on a router or firewall.
- Do not run it on a shared multi-user host. On Linux, other local users and processes on the host can reach the API container's Docker network address directly, even though its port is not published. Use a single-user host, or add a host firewall rule that limits who can reach the Docker bridge networks.
Why
Anyone who signs in — or, with AUTH=off, anyone who can reach the console at all — controls a scanner and its stored results. The loopback binding means only the host can reach it. An SSH tunnel extends that to you and no one else, using the SSH access you already control.
Related
- Docker Deployment — install, ports, and environment
- Getting Started — first project and scan