CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is evaluating a client's web application and needs to identify all possible HTTP methods supported by a specific endpoint without sending a full request body. Which Nmap script would be most appropriate for this task?

  1. Ahttp-iis-short-name-brute
  2. Bhttp-headers
  3. Chttp-enum
  4. Dhttp-methods
Show answer & explanation

Correct answer: D. http-methods

The 'http-methods' Nmap script is specifically designed to check for supported HTTP methods by sending an OPTIONS request to the target web server, which typically returns a list of allowed methods.

Why the other options are wrong

  • A. This script attempts to brute-force short filenames on IIS servers, unrelated to HTTP methods.
  • B. The http-headers script displays HTTP headers from the server, not supported methods.
  • C. The http-enum script is used for enumerating web directories and files, not HTTP methods.

Nmap http-methods script

An Nmap Scripting Engine (NSE) script used to discover the HTTP methods supported by a web server or specific web endpoint by sending an OPTIONS request.

  • Part of the Nmap Scripting Engine (NSE).
  • Sends an HTTP OPTIONS request to determine allowed methods.
  • Useful for identifying potentially insecure methods like PUT or DELETE.

Memory trick: Nmap's HTTP scripts reveal web secrets.

More Reconnaissance and Enumeration questions