CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

A penetration tester is evaluating a client's external network perimeter. They discover a web server responding on port 80. To determine if the server supports WebDAV and identify available methods, which Nmap script would be most effective?

  1. Ahttp-brute
  2. Bhttp-headers
  3. Chttp-methods
  4. Dhttp-enum
Show answer & explanation

Correct answer: C. http-methods

The nmap http-methods script specifically tests for supported HTTP methods, including those used by WebDAV, making it ideal for this scenario.

Why the other options are wrong

  • A. The http-brute script is used for brute-forcing HTTP authentication, not identifying supported methods.
  • B. The http-headers script retrieves HTTP response headers, which might indirectly reveal some information but isn't as direct as http-methods for method enumeration.
  • D. The http-enum script enumerates web directories and files, not HTTP methods.

Nmap http-methods script

An Nmap script used to discover the HTTP methods (e.g., GET, POST, PUT, DELETE, OPTIONS) supported by a web server, which can indicate WebDAV support.

  • Identifies allowed HTTP methods.
  • Useful for discovering WebDAV capabilities.
  • Part of the Nmap scripting engine (NSE).

Memory trick: Methods help you move, so Nmap's 'methods' script shows how a web server moves data.

More Reconnaissance and Enumeration questions