CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy
A penetration tester is conducting reconnaissance against a target organization's web infrastructure. They have identified the main domain and now want to discover subdomains that might not be publicly linked but are still active. Which of the following Nmap scripts is MOST effective for this task?
- Adns-srv-enum
- Bhttp-enum
- Cdns-nsec3-enum
- Ddns-brute
Show answer & explanationAnswer & explanation
Correct answer: D. dns-brute
The 'dns-brute' Nmap script is specifically designed to brute-force subdomain names using a wordlist, making it highly effective for discovering hidden or unlinked subdomains. This script is a common tool for expanding the attack surface during reconnaissance.
Why the other options are wrong
- A. This script enumerates SRV records, which define services available on a domain, not subdomains themselves.
- B. This script is used for enumerating web directories and files, not subdomains.
- C. This script attempts to enumerate DNS records using NSEC3, which is related to zone walking, not general subdomain brute-forcing.
Nmap dns-brute script
The Nmap 'dns-brute' script attempts to discover subdomains for a target domain by brute-forcing common subdomain names using a built-in wordlist or a user-provided one.
- Used for subdomain enumeration.
- Leverages wordlists for brute-forcing.
- Helps expand the attack surface by finding hidden hosts.
Memory trick: DNS-brute force opens new doors to subdomains.