CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationMedium

A penetration tester is evaluating a client's external network perimeter. They identify a public-facing web server and want to determine if it is vulnerable to directory traversal by identifying common web server paths and directories. Which Nmap script is most effective for this specific task?

  1. Ahttp-headers
  2. Bhttp-title
  3. Chttp-enum
  4. Dhttp-methods
Show answer & explanation

Correct answer: C. http-enum

The nmap http-enum script is specifically designed to enumerate common web application paths, files, and directories. This makes it highly effective for identifying potential directory traversal vulnerabilities by discovering accessible resources. Other scripts serve different purposes related to HTTP.

Why the other options are wrong

  • A. The http-headers script retrieves HTTP headers, which provides server information but not a list of directories.
  • B. The http-title script fetches the title of web pages, which is not useful for directory enumeration.
  • D. The http-methods script identifies supported HTTP methods, which is not directly related to enumerating directories for traversal.

Nmap http-enum Script

The Nmap http-enum script is used to enumerate common web application paths, files, and directories on a target web server, helping identify potential vulnerabilities like directory traversal.

  • Part of Nmap's scripting engine (NSE).
  • Scans for common web server directories and files.
  • Useful for discovering hidden or forgotten web resources.
  • Can help identify potential directory traversal or information disclosure vulnerabilities.

Memory trick: Nmap ENUMerates web paths like a detective finding hidden clues.

More Reconnaissance and Enumeration questions