CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
During a black-box penetration test, an ethical hacker identifies a web server running Apache and wants to enumerate potential hidden directories and files that might expose sensitive information. They need a tool that can perform a dictionary-based brute-force attack against the web server's paths. Which of the following tools is most suitable for this task?
- ABurp Suite's Proxy
- BNmap's `--script=http-title`
- CMetasploit's `auxiliary/scanner/http/dir_scanner`
- DHashcat
Show answer & explanationAnswer & explanation
Correct answer: C. Metasploit's `auxiliary/scanner/http/dir_scanner`
Metasploit's `auxiliary/scanner/http/dir_scanner` module is specifically designed for dictionary-based brute-forcing of web server directories and files. It allows the tester to specify a wordlist and target a web server to discover hidden paths, which aligns perfectly with the requirement.
Why the other options are wrong
- A. Burp Suite's Proxy intercepts and modifies requests, but it doesn't automate directory brute-forcing; Intruder would be used for that, not just the Proxy.
- B. Nmap's http-title script only extracts the title of a web page; it does not enumerate directories or files.
- D. Hashcat is a password cracking tool, completely unrelated to web directory enumeration.
Metasploit dir_scanner
A Metasploit auxiliary module (`auxiliary/scanner/http/dir_scanner`) used to perform dictionary-based brute-force attacks against web servers to discover hidden directories and files.
- Part of Metasploit Framework.
- Performs dictionary-based directory brute-forcing.
- Aims to discover hidden web paths.
- Useful for finding sensitive information or misconfigurations.
Memory trick: METASPLOIT Scans DIRS for Hidden Paths