CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing an external black-box assessment against a client's web application. They have identified that the web server is running on a non-standard port and is presenting a default Apache welcome page. To further enumerate the web server and identify potential misconfigurations or sensitive files, they wish to perform a comprehensive directory brute-force using a common wordlist. Which Nmap script is specifically designed for this purpose?
- Ahttp-headers
- Bhttp-methods
- Chttp-enum
- Dhttp-robots.txt
Show answer & explanationAnswer & explanation
Correct answer: C. http-enum
The `http-enum` Nmap script is specifically designed for enumerating common web application directories and files by brute-forcing a list of known paths. This aligns perfectly with the goal of finding potential misconfigurations or sensitive files on a web server running a default page.
Why the other options are wrong
- A. http-headers displays HTTP response headers, not for directory enumeration.
- B. http-methods identifies supported HTTP methods, not directories or files.
- D. http-robots.txt only checks for and parses the robots.txt file, which is a very limited form of enumeration.
Nmap http-enum Script
An Nmap Scripting Engine (NSE) script used to enumerate common web application directories and files on a web server, often via dictionary-based brute-forcing.
- Part of Nmap Scripting Engine (NSE).
- Enumerates common web paths.
- Helps discover sensitive files or misconfigurations.
- Uses dictionary-based approach.
Memory trick: ENUMerate Web Dirs for Secrets