Nuclei scan takes only about 2 seconds and does not find anything #1406
-
Hello everyone, I have a problem with nuclei-templates. I installed nuclei and I said " nuclei -ut" for it to install the templates as well. When I type "nuclei -h", it gives me the right help menu. However, when I scan a website, the scan takes only about 2-3 seconds and nuclei says this; [WRN] Use with caution. You are responsible for your actions. Every time I use nuclei, I change templates (such as vulnerabilities, cves or technologies) but this issue never changes. I give the right directory path (eg: /root/nuclei-templates/cves) and sometimes specify which exact template to use but it still gives me the same info immediately ([INF] No results found. Better luck next time!). I know that this is impossible, because when I choose "Technologies" for example, it still says the same thing. So, even if there are no vulnerabilities in the website, at least it should tell me the technologies it utilizes. Moreover, I have nuclei-templates as sn1per plugins and use them against the same website, and it works! I also updated the nuclei engine with "-u" flag but the issue still persists. Does anyone knows why this might be happening? Or even if you do not know, what is your suggestion? Note: I removed nuclei and its templates and re-installed them both a couple of times. I even went back to some of the earliest snapshots of my virtual machine and restored them in order to check the same problem. Still, I was unable to solve the issue. I updated my Kali VM snapshots before installing nuclei and its templates. Thanks for your time, suggestions and answer. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
@OmerYilmazlar is it possible you are feeding subdomains as input instead of URLs? or can you share what you feeding as input for nuclei scan? Additionally, you can see what's going on with |
Beta Was this translation helpful? Give feedback.
@OmerYilmazlar is it possible you are feeding subdomains as input instead of URLs? or can you share what you feeding as input for nuclei scan? Additionally, you can see what's going on with
-v
flag.