CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

An ethical hacker is performing an external penetration test and has identified several public-facing web servers. Before attempting any direct attacks, they want to gather as much information as possible about the web technologies in use, such as server versions, CMS, and plugins, without actively probing or sending malicious requests. Which of the following methods represents the most passive approach for this type of web technology fingerprinting?

  1. ARunning a full Nmap scan with `-sV --script=http-headers`.
  2. BReviewing HTTP headers and page source code through a web browser.
  3. CUsing `whatweb` or `wafw00f` against the target URLs.
  4. DEmploying Burp Suite's active scanner against the web application.
Show answer & explanation

Correct answer: B. Reviewing HTTP headers and page source code through a web browser.

Reviewing HTTP headers and page source code through a standard web browser is the most passive method. It relies on information sent by the server during a normal browsing session, without requiring any specialized tools to send additional probes or potentially detectable requests beyond what a typical user would generate.

Why the other options are wrong

  • A. A full Nmap scan with service version detection and HTTP header scripts is a very active and noisy method of fingerprinting.
  • C. `whatweb` and `wafw00f` are active tools that send specific probes to identify technologies and WAFs, making them more active than simply browsing.
  • D. Burp Suite's active scanner sends numerous probes and requests to identify vulnerabilities and technologies, which is a highly active approach.

Passive Web Fingerprinting

Identifying web technologies (server, CMS, libraries) by analyzing publicly available information like HTTP headers, HTML source code, and error messages, without sending specific probes.

  • Relies on information sent during normal web requests.
  • Minimizes detection risk.
  • Examples: looking at 'Server' header, 'X-Powered-By' header, HTML comments.

Memory trick: Web fingerprint: Passive browse, Active scan.

More Reconnaissance and Enumeration questions