CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy
A penetration tester is analyzing a web server that appears to be running on an unusual port, 8080. They want to determine the specific web server software (e.g., Apache, Nginx, IIS) and its version to identify potential vulnerabilities. Which Nmap command would be most effective for this task?
- Anmap -p 8080 --script http-enum <target_ip>
- Bnmap -p 8080 -sV <target_ip>
- Cnmap -p 8080 -O <target_ip>
- Dnmap -p 8080 --script http-headers <target_ip>
Show answer & explanationAnswer & explanation
Correct answer: B. nmap -p 8080 -sV <target_ip>
The '-sV' flag in Nmap is used for service version detection. When combined with '-p 8080', it will attempt to identify the specific web server software and its version running on port 8080, which is crucial for vulnerability identification.
Why the other options are wrong
- A. http-enum is for enumerating directories and files, not service versions.
- C. -O is for OS detection, not service version detection.
- D. http-headers only retrieves HTTP headers, which might contain server info but '-sV' is more comprehensive for version detection.
Nmap Service Version Detection (-sV)
The Nmap '-sV' flag enables service version detection, where Nmap attempts to determine the exact service and its version running on open ports by probing the ports with various techniques.
- Identifies the specific application and its version.
- Crucial for identifying known vulnerabilities associated with specific software versions.
- Works by sending probes and analyzing responses.
- Can be combined with port specifications.
Memory trick: Nmap flags reveal target's secrets.