CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
During a black-box penetration test, an ethical hacker identifies a web server running Apache. They suspect that the server might have directory listing enabled or contain hidden directories. To efficiently discover these, which technique involves sending requests for common directory names and analyzing the HTTP responses?
- ADNS Zone Transfer
- BPassive OS Fingerprinting
- CService Version Detection
- DWeb Directory Brute-Forcing
Show answer & explanationAnswer & explanation
Correct answer: D. Web Directory Brute-Forcing
Web directory brute-forcing (also known as directory enumeration or fuzzing) involves systematically trying common directory and file names against a web server to discover hidden or unlinked resources. This is done by analyzing the HTTP response codes (e.g., 200 OK for found, 404 Not Found for not found).
Why the other options are wrong
- A. DNS zone transfer is for enumerating DNS records, not web server directories.
- B. Passive OS fingerprinting identifies the operating system based on network traffic, not web directories.
- C. Service version detection identifies the software and version running on a port, not web directories.
Web Directory Brute-Forcing
A reconnaissance technique used to discover hidden or unlinked directories and files on a web server. It involves sending numerous HTTP requests for common directory and file names (often from a wordlist) and analyzing the HTTP response codes.
- Uses wordlists of common directory/file names.
- Analyzes HTTP response codes (e.g., 200, 301, 302, 403, 404).
- Can reveal sensitive information, configuration files, or other attack vectors.
- Tools like DirBuster, gobuster, or wfuzz are commonly used.
Memory trick: Brute-forcing directories is like trying every key on a keychain for hidden doors.