CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
A penetration tester is performing a black-box assessment against a client's external web servers. They discover that one server is running Apache HTTP Server. To further enumerate potential vulnerabilities, the tester wants to identify common, non-standard web directories and files that might expose sensitive information. Which Nmap script category would be most effective for this type of web enumeration without relying on a full vulnerability scanner?
- Ahttp-enum
- Bauth
- Cvuln
- Ddiscovery
Show answer & explanationAnswer & explanation
Correct answer: A. http-enum
The `http-enum` Nmap script is specifically designed to enumerate common web directories and files on HTTP/HTTPS servers. It attempts to find various resources that might be exposed, such as administrative interfaces, backup files, or sensitive documents, which aligns perfectly with the goal of finding non-standard web content for further investigation.
Why the other options are wrong
- B. The `auth` script category tests for authentication bypasses or weak credentials, not for directory/file enumeration.
- C. The `vuln` script category checks for specific known vulnerabilities, which is broader than just directory enumeration and might be more 'noisy' than desired for initial enumeration.
- D. The `discovery` category is very broad and might include various types of discovery, but `http-enum` is more specific and directly addresses the need for web directory enumeration.
Nmap http-enum Script
The `http-enum` Nmap Scripting Engine (NSE) script attempts to enumerate common web directories and files on HTTP/HTTPS servers, often using a predefined wordlist.
- Part of the 'discovery' and 'safe' categories.
- Useful for finding hidden or forgotten web content.
- Can help identify potential attack vectors or information disclosure.
Memory trick: Nmap scripts: Auth, Vuln, Discovery, HTTP Enum.