CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing reconnaissance against a target organization. They have identified several public-facing web servers and want to gather information about their SSL/TLS certificates, such as issuer, expiration dates, and supported cipher suites. Which Nmap script would be MOST effective for automatically extracting this type of information?
- Atls-alpn
- Bhttp-sitemap-generator
- Cssl-enum-ciphers
- Dssl-cert
Show answer & explanationAnswer & explanation
Correct answer: D. ssl-cert
The 'ssl-cert' Nmap script is specifically designed to retrieve and display information about the SSL/TLS certificate used by a service. This includes details like the issuer, subject, validity period (expiration), and other critical certificate attributes.
Why the other options are wrong
- A. This script enumerates Application-Layer Protocol Negotiation (ALPN) protocols, not certificate details.
- B. This script generates a sitemap for a web server, unrelated to SSL/TLS certificate details.
- C. This script enumerates supported SSL/TLS cipher suites, but not the certificate details like issuer or expiration.
Nmap ssl-cert script
The Nmap 'ssl-cert' script retrieves and displays detailed information about the SSL/TLS certificate presented by a service, including issuer, subject, validity dates, serial number, and public key details.
- Extracts SSL/TLS certificate details.
- Provides issuer, subject, validity, and expiration dates.
- Crucial for identifying certificate misconfigurations or weaknesses.
Memory trick: The SSL-cert reveals all about the certificate's identity.