CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing a black-box assessment against a client's external network. They have identified several public-facing web servers and want to gather information about their SSL/TLS certificates, such as expiration dates, common names, and potentially alternative subject names, which might reveal additional subdomains. Which Nmap script is most suitable for this task?
- Atls-alpn
- Bssl-cert
- Cssl-enum-ciphers
- Dhttp-headers
Show answer & explanationAnswer & explanation
Correct answer: B. ssl-cert
The `ssl-cert` Nmap script is specifically designed to extract and display detailed information about the SSL/TLS certificate presented by a server, including expiration dates, issuer, subject common name, and Subject Alternative Names (SANs), which often reveal associated subdomains.
Why the other options are wrong
- A. `tls-alpn` is for Application-Layer Protocol Negotiation (ALPN) information, not certificate details.
- C. `ssl-enum-ciphers` enumerates supported SSL/TLS ciphers, not certificate details.
- D. `http-headers` retrieves standard HTTP headers, not SSL/TLS certificate information.
Nmap ssl-cert Script
An Nmap Scripting Engine (NSE) script that retrieves and displays detailed information from a server's SSL/TLS certificate. This includes common name (CN), issuer, validity period, and Subject Alternative Names (SANs), which can be useful for subdomain enumeration.
- Extracts SSL/TLS certificate details.
- Provides common name, issuer, validity, and SANs.
- SANs can reveal additional subdomains.
- Useful for identifying certificate misconfigurations or expired certificates.
Memory trick: SSL-cert is like reading the ID card of the web server.