CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard

A penetration tester is performing a black-box assessment against a web server. They discover a login form and want to test for common username enumeration vulnerabilities by trying a list of usernames and observing the server's responses. Which Metasploit auxiliary module is specifically designed for this type of web enumeration?

  1. Aauxiliary/scanner/http/http_login
  2. Bauxiliary/scanner/http/dir_scanner
  3. Cauxiliary/scanner/http/wordpress_login_enum
  4. Dauxiliary/scanner/http/http_version
Show answer & explanation

Correct answer: C. auxiliary/scanner/http/wordpress_login_enum

While 'http_login' is a general module, 'wordpress_login_enum' is specifically designed to enumerate valid usernames on WordPress login pages by observing subtle differences in error messages, which is a classic example of username enumeration vulnerability on web login forms.

Why the other options are wrong

  • A. http_login is a general module for brute-forcing login credentials, not primarily for enumeration by error messages.
  • B. dir_scanner is for enumerating directories and files, not usernames.
  • D. This module identifies HTTP server versions, not for login enumeration.

Metasploit WordPress Username Enumeration

Metasploit's 'auxiliary/scanner/http/wordpress_login_enum' module is used to identify valid usernames on WordPress sites by analyzing differences in error messages when invalid usernames are submitted to the login page.

  • Targets WordPress login forms.
  • Exploits differences in error messages for valid vs. invalid usernames.
  • A specific example of username enumeration vulnerability.
  • Part of Metasploit's auxiliary scanner modules.

Memory trick: Metasploit scans web forms for secrets.

More Reconnaissance and Enumeration questions