CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy
A penetration tester is evaluating a client's external network perimeter. They discover a web server responding on port 80. To determine if the server supports WebDAV and identify available methods, which Nmap script would be most effective?
- Ahttp-brute
- Bhttp-headers
- Chttp-methods
- Dhttp-enum
Show answer & explanationAnswer & explanation
Correct answer: C. http-methods
The nmap http-methods script specifically tests for supported HTTP methods, including those used by WebDAV, making it ideal for this scenario.
Why the other options are wrong
- A. The http-brute script is used for brute-forcing HTTP authentication, not identifying supported methods.
- B. The http-headers script retrieves HTTP response headers, which might indirectly reveal some information but isn't as direct as http-methods for method enumeration.
- D. The http-enum script enumerates web directories and files, not HTTP methods.
Nmap http-methods script
An Nmap script used to discover the HTTP methods (e.g., GET, POST, PUT, DELETE, OPTIONS) supported by a web server, which can indicate WebDAV support.
- Identifies allowed HTTP methods.
- Useful for discovering WebDAV capabilities.
- Part of the Nmap scripting engine (NSE).
Memory trick: Methods help you move, so Nmap's 'methods' script shows how a web server moves data.