CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationHard
During a penetration test, a web server is discovered to be running an older version of Apache. The penetration tester wants to identify if directory listing is enabled or if there are any sensitive files exposed. They also need to understand the directory structure. Which Nmap script, potentially combined with others, would be MOST effective for enumerating web directories and files?
- Ahttp-fingerprint
- Bhttp-enum
- Chttp-brute
- Dhttp-robots.txt
Show answer & explanationAnswer & explanation
Correct answer: B. http-enum
The 'http-enum' Nmap script is specifically designed to enumerate common web directories and files. It attempts to discover resources that might be exposed, including those that indicate directory listing or sensitive information, making it highly effective for understanding the directory structure and finding exposed assets.
Why the other options are wrong
- A. This script attempts to fingerprint web servers and applications, but not to enumerate specific directories or files.
- C. This script is used for brute-forcing HTTP authentication, not for enumerating directories or files.
- D. This script only fetches and parses the robots.txt file, which might reveal some paths but is not a comprehensive directory enumerator.
Nmap http-enum script
The Nmap 'http-enum' script attempts to discover common web directories and files on a target web server. It can reveal exposed resources, misconfigurations like directory listing, and sensitive information, aiding in web application reconnaissance.
- Enumerates common web directories and files.
- Helps identify exposed resources and misconfigurations.
- Useful for understanding the web application's structure.
Memory trick: HTTP-enum lists every room in the web house.