Vulnerability assessment begins after a service has been identified: you still need to connect its version to public exploit references, check the web server for unsafe defaults, and collect findings that can be reviewed later. This course develops that workflow through hands-on use of searchsploit, Nikto, and Nuclei.
You will work against local lab targets, refine noisy scans, preserve results in report files, and inspect the evidence behind a finding. A final challenge asks you to apply the core commands independently to assess supplied Nginx and vsftpd versions and a local web service.
What You Will Learn
- Update the local Exploit Database and Nuclei template collection before an assessment.
- Query Exploit-DB for exact software versions with
searchsploit. - Filter
searchsploitresults, mirror an exploit file, and inspect its source without executing it. - Run baseline and category-focused Nikto scans against a local web server.
- Export Nikto findings to HTML and extract relevant evidence with command-line tools.
- Run general and tag-filtered Nuclei scans, interpret finding metadata, and save the output.
- Complete a local vulnerability audit by recording searches for Nginx and vsftpd and a Nikto scan.
Who This Course Is For
This intermediate course is for security learners who have completed basic host and service discovery and want a practical introduction to vulnerability assessment. It suits aspiring penetration testers, defensive analysts, and administrators who need to understand what scanner results do—and do not—prove.
Prerequisites: Comfort with a Linux terminal, basic shell redirection, URLs and web-server concepts, and software/service version identification.
Learning environment: An Ubuntu 22.04 terminal with searchsploit, Nikto, and Nuclei available, plus local web targets prepared for the labs. Database and template update exercises contact their upstream repositories.
Frequently Asked Questions
Does a scanner finding prove that a vulnerability is exploitable?
No. Nikto and Nuclei findings, and even a matching Exploit-DB entry, are evidence for further investigation. Version accuracy, target configuration, template quality, and exploit prerequisites still need to be checked before a risk is confirmed.
Will I exploit a vulnerable service in this course?
No. You will search for public exploit references and mirror one source file for inspection, but the course does not ask you to run exploit code. The focus is assessment, evidence collection, and safe review.
Do the scans target public systems?
No. The practical scans use web services hosted inside the course environment at localhost, including a Nuclei target on port 8080.
How are the three tools used differently?
searchsploit correlates known software versions with entries in a local copy of Exploit-DB. Nikto performs broad web-server checks that can be narrowed by test category, while Nuclei runs template-driven checks that can be filtered by tags such as exposure.





