CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is analyzing a web application. They notice that certain HTTP headers, such as 'Server' and 'X-Powered-By', are present in responses and reveal specific technologies. They want to automate the collection of these banners and identify the underlying web server and programming languages. Which Nmap script is specifically designed for this type of web enumeration?
- Ahttp-headers
- Bhttp-devframework
- Chttp-title
- Dhttp-server-header
Show answer & explanationAnswer & explanation
Correct answer: A. http-headers
The 'http-headers' Nmap script is used to retrieve and display all HTTP response headers from a web server. This is crucial for identifying technologies through banners like 'Server', 'X-Powered-By', and other informative headers, aiding in web enumeration and fingerprinting.
Why the other options are wrong
- B. This is not a standard Nmap script.
- C. This script only retrieves the title of a web page.
- D. While this might sound relevant, 'http-headers' is the general script for all headers, including the specific 'Server' header.
Nmap http-headers script
The Nmap 'http-headers' script retrieves and displays all HTTP response headers from a web server, which can reveal valuable information about the server software, frameworks, and technologies in use.
- Collects all HTTP response headers.
- Useful for web server fingerprinting.
- Identifies 'Server', 'X-Powered-By', and other informative banners.
Memory trick: HTTP headers reveal the web server's true identity.