CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is performing a black-box assessment against a client's web application. They discover that the application uses a custom error page that provides little information. To gather more details about potential vulnerabilities, the tester wants to identify common web directories and files that might exist on the server. Which Nmap script is most effective for this purpose?

  1. Ahttp-title
  2. Bhttp-enum
  3. Chttp-devframework
  4. Dhttp-headers
Show answer & explanation

Correct answer: B. http-enum

The `http-enum` Nmap script is designed to enumerate various common web directories and files, including those used by popular web applications, by brute-forcing or checking for known paths, which is crucial for discovering hidden resources.

Why the other options are wrong

  • A. The `http-title` script simply retrieves the title of a web page, not relevant for directory enumeration.
  • C. The `http-devframework` script attempts to detect web development frameworks, not to enumerate directories.
  • D. The `http-headers` script retrieves HTTP headers, useful for server info but not directory enumeration.

Nmap http-enum Script

An Nmap Scripting Engine (NSE) script used for enumerating common web directories and files on HTTP(S) servers. It attempts to discover hidden or less obvious paths that might lead to sensitive information or vulnerabilities.

  • Part of Nmap Scripting Engine (NSE).
  • Enumerates common web directories and files.
  • Useful for discovering hidden resources or misconfigurations.
  • Can be used for black-box web application assessments.

Memory trick: Enum-eration is like exploring every room in the web house.

More Reconnaissance and Enumeration questions