CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester is performing a black-box assessment against a client's external web servers. They discover that one server is running Apache HTTP Server. To further enumerate potential vulnerabilities, the tester wants to identify common, non-standard web directories and files that might expose sensitive information. Which Nmap script category would be most effective for this type of web enumeration without relying on a full vulnerability scanner?

  1. Ahttp-enum
  2. Bauth
  3. Cvuln
  4. Ddiscovery
Show answer & explanation

Correct answer: A. http-enum

The `http-enum` Nmap script is specifically designed to enumerate common web directories and files on HTTP/HTTPS servers. It attempts to find various resources that might be exposed, such as administrative interfaces, backup files, or sensitive documents, which aligns perfectly with the goal of finding non-standard web content for further investigation.

Why the other options are wrong

  • B. The `auth` script category tests for authentication bypasses or weak credentials, not for directory/file enumeration.
  • C. The `vuln` script category checks for specific known vulnerabilities, which is broader than just directory enumeration and might be more 'noisy' than desired for initial enumeration.
  • D. The `discovery` category is very broad and might include various types of discovery, but `http-enum` is more specific and directly addresses the need for web directory enumeration.

Nmap http-enum Script

The `http-enum` Nmap Scripting Engine (NSE) script attempts to enumerate common web directories and files on HTTP/HTTPS servers, often using a predefined wordlist.

  • Part of the 'discovery' and 'safe' categories.
  • Useful for finding hidden or forgotten web content.
  • Can help identify potential attack vectors or information disclosure.

Memory trick: Nmap scripts: Auth, Vuln, Discovery, HTTP Enum.

More Reconnaissance and Enumeration questions