CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing a black-box assessment against a client's external network. They have identified several public-facing web servers and want to gather information about their SSL/TLS certificates, such as expiration dates, common names, and potentially alternative subject names, which might reveal additional subdomains. Which Nmap script is most suitable for this task?

  1. Atls-alpn
  2. Bssl-cert
  3. Cssl-enum-ciphers
  4. Dhttp-headers
Show answer & explanation

Correct answer: B. ssl-cert

The `ssl-cert` Nmap script is specifically designed to extract and display detailed information about the SSL/TLS certificate presented by a server, including expiration dates, issuer, subject common name, and Subject Alternative Names (SANs), which often reveal associated subdomains.

Why the other options are wrong

  • A. `tls-alpn` is for Application-Layer Protocol Negotiation (ALPN) information, not certificate details.
  • C. `ssl-enum-ciphers` enumerates supported SSL/TLS ciphers, not certificate details.
  • D. `http-headers` retrieves standard HTTP headers, not SSL/TLS certificate information.

Nmap ssl-cert Script

An Nmap Scripting Engine (NSE) script that retrieves and displays detailed information from a server's SSL/TLS certificate. This includes common name (CN), issuer, validity period, and Subject Alternative Names (SANs), which can be useful for subdomain enumeration.

  • Extracts SSL/TLS certificate details.
  • Provides common name, issuer, validity, and SANs.
  • SANs can reveal additional subdomains.
  • Useful for identifying certificate misconfigurations or expired certificates.

Memory trick: SSL-cert is like reading the ID card of the web server.

More Reconnaissance and Enumeration questions