CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester has identified a web server running Apache and wants to enumerate potential directories and files that might expose sensitive information. They want to use a tool that can perform dictionary-based brute-forcing of common web paths and extensions. Which tool would be most effective for this task?

  1. ADirb or Gobuster
  2. BHashcat
  3. CNmap's `http-enum` script
  4. DMetasploit's `auxiliary/scanner/http/http_version` module
Show answer & explanation

Correct answer: A. Dirb or Gobuster

Dirb and Gobuster are specialized web content scanners designed to brute-force directories and files on web servers using wordlists, making them highly effective for discovering hidden or forgotten resources.

Why the other options are wrong

  • B. Hashcat is a password cracking tool, completely unrelated to web directory and file enumeration.
  • C. Nmap's `http-enum` script can discover common web paths, but dedicated tools like Dirb or Gobuster are often more robust and configurable for extensive dictionary-based brute-forcing.
  • D. Metasploit's `http_version` module is primarily for identifying web server versions, not for enumerating directories and files.

Web Directory Brute-Forcing

Web directory brute-forcing involves systematically attempting to access common or guessed directory and file names on a web server using wordlists, aiming to discover hidden or unlinked resources.

  • Uses wordlists for common paths/extensions
  • Helps discover sensitive files (e.g., backups, configs)
  • Tools like Dirb and Gobuster are specialized for this

Memory trick: Dirb and Gobuster are the Detectives of Directories.

More Reconnaissance and Enumeration questions