CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

A penetration tester is evaluating a client's web server. They have discovered that the server is configured to allow directory listing by default. To efficiently enumerate all accessible directories and files, including those that might contain sensitive information, which Nmap script would be most suitable?

  1. Ahttp-headers
  2. Bhttp-brute
  3. Chttp-methods
  4. Dhttp-enum
Show answer & explanation

Correct answer: D. http-enum

The nmap http-enum script is specifically designed to enumerate web directories and files by brute-forcing common paths and checking for known vulnerabilities, making it ideal for discovering sensitive information when directory listing is enabled.

Why the other options are wrong

  • A. The http-headers script retrieves HTTP response headers, which might indirectly reveal some information but isn't for directory enumeration.
  • B. The http-brute script is used for brute-forcing HTTP authentication, not for directory enumeration.
  • C. The http-methods script discovers supported HTTP methods (e.g., GET, POST), not directory contents.

Nmap http-enum script

An Nmap script that enumerates common web server directories, files, and known vulnerabilities by brute-forcing paths and checking for defaults.

  • Identifies common web paths and files.
  • Useful for discovering exposed directories and sensitive information.
  • Part of the Nmap scripting engine (NSE).

Memory trick: To ENUMerate web directories, use the 'http-enum' script.

More Reconnaissance and Enumeration questions