CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

During a black-box penetration test, an ethical hacker identifies a web server running Apache and wants to enumerate potential hidden directories and files that might expose sensitive information. They need a tool that can perform a dictionary-based brute-force attack against the web server's paths. Which of the following tools is most suitable for this task?

  1. ABurp Suite's Proxy
  2. BNmap's `--script=http-title`
  3. CMetasploit's `auxiliary/scanner/http/dir_scanner`
  4. DHashcat
Show answer & explanation

Correct answer: C. Metasploit's `auxiliary/scanner/http/dir_scanner`

Metasploit's `auxiliary/scanner/http/dir_scanner` module is specifically designed for dictionary-based brute-forcing of web server directories and files. It allows the tester to specify a wordlist and target a web server to discover hidden paths, which aligns perfectly with the requirement.

Why the other options are wrong

  • A. Burp Suite's Proxy intercepts and modifies requests, but it doesn't automate directory brute-forcing; Intruder would be used for that, not just the Proxy.
  • B. Nmap's http-title script only extracts the title of a web page; it does not enumerate directories or files.
  • D. Hashcat is a password cracking tool, completely unrelated to web directory enumeration.

Metasploit dir_scanner

A Metasploit auxiliary module (`auxiliary/scanner/http/dir_scanner`) used to perform dictionary-based brute-force attacks against web servers to discover hidden directories and files.

  • Part of Metasploit Framework.
  • Performs dictionary-based directory brute-forcing.
  • Aims to discover hidden web paths.
  • Useful for finding sensitive information or misconfigurations.

Memory trick: METASPLOIT Scans DIRS for Hidden Paths

More Reconnaissance and Enumeration questions