EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium
An ethical hacker is performing reconnaissance on a web server and uses `nmap -p 80,443 --script http-enum <target_IP>`. What specific information is the hacker primarily attempting to discover with this Nmap script?
- AHidden files and directories on the web server.
- BOpen ports for other services beyond HTTP/HTTPS.
- CCommon web application vulnerabilities like SQL injection points.
- DThe type and version of the web server software.
Show answer & explanationAnswer & explanation
Correct answer: A. Hidden files and directories on the web server.
The `http-enum` Nmap script is specifically designed to enumerate applications, directories, and files on web servers. It attempts to discover hidden or common resources that might reveal sensitive information or provide attack vectors.
Why the other options are wrong
- B. The `-p 80,443` flag specifies ports, but the `http-enum` script focuses on web content, not other services.
- C. While enumeration can lead to discovering vulnerabilities, `http-enum` itself focuses on resource discovery, not direct vulnerability identification like SQL injection.
- D. Web server type and version are typically found using scripts like `http-headers` or by banner grabbing, not `http-enum`.
Nmap http-enum Script
An Nmap script used to enumerate applications, directories, and files on web servers by attempting to find common or hidden resources.
- Part of Nmap's Scripting Engine (NSE).
- Helps discover potential attack surface.
- Uses wordlists for common paths and filenames.
Memory trick: Enum-erate means 'list everything' for the web.