EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesEasy
A security analyst is performing an external penetration test against a client's public-facing web server. They are attempting to identify the web server software and its version without directly connecting to the server. Which of the following reconnaissance techniques would be most effective for this passive information gathering?
- AAnalyzing HTTP headers from publicly accessible web pages.
- BUsing a packet sniffer to capture traffic to and from the web server.
- CPerforming an Nmap TCP SYN scan against common web ports.
- DConducting a full DNS zone transfer for the target domain.
Show answer & explanationAnswer & explanation
Correct answer: A. Analyzing HTTP headers from publicly accessible web pages.
Analyzing HTTP headers is a passive reconnaissance technique that allows an attacker to gather information about the web server software and its version without directly interacting with the server in an intrusive way. This information is often included in the 'Server' header field.
Why the other options are wrong
- B. Using a packet sniffer requires being on the target's network or a man-in-the-middle position, which isn't typically 'external' passive reconnaissance without direct connection.
- C. An Nmap TCP SYN scan is an active scanning technique, not passive reconnaissance.
- D. A DNS zone transfer is used to gather domain information and might be active if not properly configured, but it doesn't directly reveal web server software versions from HTTP headers.
HTTP Header Analysis
The process of examining the metadata exchanged between a web browser and a web server, often revealing server software, versions, and configurations.
- Passive reconnaissance technique.
- Information found in 'Server' header.
- Does not directly interact with the server intrusively.
Memory trick: Headers are like nametags for web servers.