CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is evaluating a web application for potential vulnerabilities. They notice that the application uses an older version of Apache and wants to identify if any known directories or files are exposed due to common misconfigurations or default installations. Which Nmap script is specifically designed to enumerate common web directories and files based on known patterns and wordlists?

  1. Ahttp-waf-detect
  2. Bhttp-methods
  3. Chttp-title
  4. Dhttp-enum
Show answer & explanation

Correct answer: D. http-enum

The `http-enum` Nmap script is specifically designed for web server enumeration, attempting to discover common web directories, files, and scripts by checking for known paths, including those often exposed by misconfigured or outdated web servers like older Apache versions.

Why the other options are wrong

  • A. `http-waf-detect` attempts to detect Web Application Firewalls, not enumerate directories.
  • B. `http-methods` identifies supported HTTP methods (e.g., GET, POST, PUT), not directories.
  • C. `http-title` retrieves the title of the web page, which is not for directory enumeration.

Nmap http-enum Script

An Nmap Scripting Engine (NSE) script that enumerates common web directories and files on HTTP(S) servers. It's highly effective for discovering hidden resources, default installation paths, and potential misconfigurations on web servers.

  • Uses wordlists to test for common paths.
  • Identifies directories, files, and scripts.
  • Useful for finding sensitive information or entry points.
  • Works against common web servers like Apache, Nginx, IIS.

Memory trick: Enum-eration: explore every room in the web house for secrets.

More Reconnaissance and Enumeration questions