CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is evaluating a web server that uses an old version of Apache. They suspect that directory listing might be enabled on some parts of the server, potentially exposing sensitive files. Which of the following web enumeration techniques would be most effective for quickly identifying if directory listing is enabled on common web paths?
- AUsing `nmap --script http-enum`.
- BBrute-forcing subdomains with `sublist3r`.
- CPerforming a UDP scan with `nmap -sU`.
- DAttempting a zone transfer with `dig`.
Show answer & explanationAnswer & explanation
Correct answer: A. Using `nmap --script http-enum`.
The `http-enum` Nmap script is specifically designed to enumerate common web directories and files, and will often detect if directory listing is enabled when it attempts to access a directory that doesn't have an index file. This provides a quick and effective way to identify such misconfigurations.
Why the other options are wrong
- B. Subdomain brute-forcing (`sublist3r`) is for finding additional subdomains, not for checking directory listings on a known web server.
- C. A UDP scan (`nmap -sU`) is for finding open UDP ports and services, not for web directory enumeration.
- D. Zone transfers are for DNS enumeration, not for identifying web server directory listings.
Nmap's http-enum and Directory Listing
Nmap's `http-enum` script actively probes a web server for common directories and files. When it encounters a directory without an index page and directory listing is enabled, the server's response (e.g., an HTML page listing contents) will be detected and reported by the script.
- Automates discovery of common web paths.
- Can identify misconfigured directory listings.
- Provides quick insights into exposed web content.
Memory trick: Web enum: Nmap http-enum finds open directories.