Skip to content

Remote Access ​

Use the console from another computer through an SSH tunnel. Do not open it to the network.

Do not expose Nikto Platform to the internet or untrusted networks

Nikto Platform is beta software. Do not expose it to the internet or to any network you do not trust, even with operator login enabled. Beta software has not had the hardening a public-facing service needs. It is also a scanner: whoever can use it can send traffic from your machine and read everything it has found.

The console now requires a username and password before it shows any project data, but that is not a substitute for keeping it off untrusted networks — there is one account, no per-project access control, and a local attacker who reaches the sign-in screen can still lock it out (see Locked out? for signing in from the host anyway).

If AUTH=off is set in .env, there is no login at all, and anyone who can reach the console has full control:

  • Run scans from your machine against any target
  • Read every finding, and the credentials and headers stored with scans
  • Change settings, including proxies and project settings

Default setup ​

The console is published on 127.0.0.1 port 3001 only (UI_PORT in .env). Only the machine that runs Docker can open it. Other machines on the network cannot connect, and no other part of the stack publishes a port.

If you changed UI_PORT, use your port wherever this page says 3001.

Use an SSH tunnel ​

An SSH tunnel forwards a port on your own computer to the console's loopback address on the scanner host. The console stays private, and SSH handles authentication and encryption.

  1. On your own computer, run:

    bash
    ssh -N -L 3001:127.0.0.1:3001 user@scanner-host

    Replace user@scanner-host with your SSH login for the machine that runs Nikto Platform.

  2. Leave that command running. -N tells SSH to forward the port without opening a remote shell, so the terminal appears to hang. That is expected.

  3. Open http://localhost:3001 in a browser on your own computer.

  4. Press Ctrl+C in the terminal to close the tunnel when you are done.

The first 3001 is the port on your computer. Change it if that port is in use:

bash
ssh -N -L 8443:127.0.0.1:3001 user@scanner-host

Then open http://localhost:8443. The 127.0.0.1:3001 part stays the same, because it is the console's address on the scanner host.

Windows ​

  • PowerShell: Windows 10 and later include the OpenSSH client. The ssh command above works the same way.
  • PuTTY: under Connection → SSH → Tunnels, set Source port to 3001 and Destination to 127.0.0.1:3001, click Add, then open the session. Browse to http://localhost:3001 while the session is open.

Keep the tunnel open ​

  • ssh -f -N -L 3001:127.0.0.1:3001 user@scanner-host sends the tunnel to the background after you log in. Stop it by ending that ssh process.
  • autossh, where installed, restarts the tunnel if the connection drops.

Other private options ​

A VPN or overlay network you already trust, such as WireGuard or Tailscale, can carry the SSH tunnel. Keep the console on 127.0.0.1 and run the tunnel over that network. The VPN limits who can reach the host; it does not add a login to the console.

What not to do ​

  • Do not change the port binding. Leave 127.0.0.1: in front of the console port in the compose file. Changing it to 0.0.0.0, or removing it, opens the console to every network the host is on.
  • Do not put the console behind a public reverse proxy, and do not port-forward it on a router or firewall.
  • Do not run it on a shared multi-user host. On Linux, other local users and processes on the host can reach the API container's Docker network address directly, even though its port is not published. Use a single-user host, or add a host firewall rule that limits who can reach the Docker bridge networks.

Why ​

Anyone who signs in — or, with AUTH=off, anyone who can reach the console at all — controls a scanner and its stored results. The loopback binding means only the host can reach it. An SSH tunnel extends that to you and no one else, using the SSH access you already control.

Proprietary software. Licensed for use under the End User License Agreement.