CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is evaluating a client's web application and discovers several HTTP headers that reveal specific server technologies and version numbers, such as 'Server: Apache/2.4.41 (Ubuntu)' and 'X-Powered-By: PHP/7.4.3'. While this information is useful, the tester wants to confirm if there are any other less obvious headers or HTTP methods supported by the server that could indicate additional vulnerabilities or configuration issues. Which Nmap script would be most effective for this specific task?

  1. Ahttp-enum
  2. Bhttp-version-detection
  3. Chttp-methods
  4. Dhttp-headers
Show answer & explanation

Correct answer: C. http-methods

The 'http-methods' Nmap script specifically sends OPTIONS requests to the web server to identify all supported HTTP methods (e.g., GET, POST, PUT, DELETE, TRACE, OPTIONS). Discovering methods like PUT or DELETE can indicate potential vulnerabilities if they are misconfigured.

Why the other options are wrong

  • A. http-enum is used for enumerating web application directories and files, not HTTP methods or headers.
  • B. http-version-detection is part of the service version detection (-sV) and focuses on the server software version, not supported methods.
  • D. http-headers displays common HTTP headers, but the question asks about *other* headers and *methods* beyond basic server info.

Nmap http-methods Script

An Nmap script that sends HTTP OPTIONS requests to a web server to enumerate all supported HTTP methods, which can reveal potential misconfigurations or attack surfaces.

  • Sends HTTP OPTIONS request.
  • Identifies supported HTTP methods (GET, POST, PUT, DELETE, TRACE, etc.).
  • Helps discover potential vulnerabilities due to insecure method configurations.

Memory trick: METHODS Reveal Hidden Web Capabilities

More Reconnaissance and Enumeration questions