CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing an external black-box assessment against a client's web application. They have identified that the web server is running on a non-standard port and is presenting a default Apache welcome page. To further enumerate the web server and identify potential misconfigurations or sensitive files, they wish to perform a comprehensive directory brute-force using a common wordlist. Which Nmap script is specifically designed for this purpose?

  1. Ahttp-headers
  2. Bhttp-methods
  3. Chttp-enum
  4. Dhttp-robots.txt
Show answer & explanation

Correct answer: C. http-enum

The `http-enum` Nmap script is specifically designed for enumerating common web application directories and files by brute-forcing a list of known paths. This aligns perfectly with the goal of finding potential misconfigurations or sensitive files on a web server running a default page.

Why the other options are wrong

  • A. http-headers displays HTTP response headers, not for directory enumeration.
  • B. http-methods identifies supported HTTP methods, not directories or files.
  • D. http-robots.txt only checks for and parses the robots.txt file, which is a very limited form of enumeration.

Nmap http-enum Script

An Nmap Scripting Engine (NSE) script used to enumerate common web application directories and files on a web server, often via dictionary-based brute-forcing.

  • Part of Nmap Scripting Engine (NSE).
  • Enumerates common web paths.
  • Helps discover sensitive files or misconfigurations.
  • Uses dictionary-based approach.

Memory trick: ENUMerate Web Dirs for Secrets

More Reconnaissance and Enumeration questions