CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium
A penetration tester is performing an external black-box assessment. They have identified a web server that appears to be running on an unusual port (e.g., 8080) and want to gather as much information as possible about the web server software, including its version, operating system, and any common scripts or directories, without being overly aggressive. Which Nmap command would provide a good balance of detail and stealth for this initial reconnaissance?
- Anmap -A -p 8080 <target_IP>
- Bnmap -sV --script=http-enum -p 8080 <target_IP>
- Cnmap -sS -p 8080 <target_IP>
- Dnmap -sV -O -p 8080 <target_IP>
Show answer & explanationAnswer & explanation
Correct answer: B. nmap -sV --script=http-enum -p 8080 <target_IP>
The command `nmap -sV --script=http-enum -p 8080 <target_IP>` uses service version detection (`-sV`) to identify the web server software and version, and the `http-enum` script to discover common directories and files. This combination provides detailed web-specific information without the full aggression of `-A` or the limited detail of a basic SYN scan.
Why the other options are wrong
- A. -A (Aggressive scan) is generally too noisy for a 'not overly aggressive' requirement, as it includes OS detection, version detection, script scanning, and traceroute.
- C. -sS (SYN scan) only identifies open ports; it does not gather service versions, OS details, or web enumeration information.
- D. -O (OS detection) can be more aggressive and less specific to web enumeration; `-sV` is good but lacks web-specific enumeration.
Nmap Focused Web Enumeration
Using Nmap's service version detection (`-sV`) combined with web-specific scripts like `http-enum` to gather detailed information about a web server, including software versions and common directories, without being overly aggressive.
- `-sV` for service/version detection.
- `--script=http-enum` for directory and file enumeration.
- Provides focused web-specific reconnaissance.
- Less aggressive than a full `-A` scan.
Memory trick: Service Version + HTTP Enum = Web Insight