CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing reconnaissance against a target organization. They have identified several public-facing web servers and want to gather information about their SSL/TLS certificates, such as issuer, expiration dates, and supported cipher suites. Which Nmap script would be MOST effective for automatically extracting this type of information?

  1. Atls-alpn
  2. Bhttp-sitemap-generator
  3. Cssl-enum-ciphers
  4. Dssl-cert
Show answer & explanation

Correct answer: D. ssl-cert

The 'ssl-cert' Nmap script is specifically designed to retrieve and display information about the SSL/TLS certificate used by a service. This includes details like the issuer, subject, validity period (expiration), and other critical certificate attributes.

Why the other options are wrong

  • A. This script enumerates Application-Layer Protocol Negotiation (ALPN) protocols, not certificate details.
  • B. This script generates a sitemap for a web server, unrelated to SSL/TLS certificate details.
  • C. This script enumerates supported SSL/TLS cipher suites, but not the certificate details like issuer or expiration.

Nmap ssl-cert script

The Nmap 'ssl-cert' script retrieves and displays detailed information about the SSL/TLS certificate presented by a service, including issuer, subject, validity dates, serial number, and public key details.

  • Extracts SSL/TLS certificate details.
  • Provides issuer, subject, validity, and expiration dates.
  • Crucial for identifying certificate misconfigurations or weaknesses.

Memory trick: The SSL-cert reveals all about the certificate's identity.

More Reconnaissance and Enumeration questions