Enumeration Flashcards

(13 cards)

1
Q

Nmap shows 22, 80, 445 open. You have 30 minutes. What is the best prioritization?

A

Start with web (80) + SMB (445) quick enum in parallel notes; keep SSH for post-foothold/creds.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Nmap shows 80 open but browser redirects to a hostname you can’t resolve. Next step?

A

Add the hostname to /etc/hosts pointing to the target IP and retry.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Nmap shows 445 open but SMB share listing fails anonymously. What do you do?

A

Enumerate for null-session info, check SMB signing/auth requirements, and pivot to credential discovery elsewhere.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Web server responds 403 on /. You suspect hidden content. Best next step?

A

Run content discovery with appropriate extensions and check robots.txt, sitemap, and vhosts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

HTTP returns 200 but app is blank until a cookie is set. Next step?

A

Inspect headers/cookies with proxy, follow auth/session flow, then enumerate authenticated paths if possible.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Service banners conflict (Apache vs nginx). What’s best?

A

Trust behavior: verify with HTTP responses, headers, and TLS/certs; document uncertainty.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

You get “filtered” for all ports on one host. Other hosts scan fine. What do you check?

A

Host-specific firewall rules or rate limiting; try slower scan and verify target reachability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Directory brute forcing returns many 301 redirects. How do you avoid missing real content?

A

Follow redirects and normalize trailing slashes; ensure tool handles 301/302 correctly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

You suspect an API exists but no docs. Best enum approach?

A

Look for /api paths, JS files, OpenAPI/Swagger endpoints, and intercept app calls via proxy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

SNMP is open (161/udp). What’s a safe next step?

A

Try read-only community strings (authorized) and enumerate system/network info via SNMP queries.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

SMTP is open (25). What’s a useful enumeration goal?

A

Identify server type and whether user enumeration/relay is possible (within rules).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

You find a subdomain that resolves to the same IP but different app. What should you do?

A

Treat it as separate vhost: enumerate its unique paths/auth and document.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Your scans trigger WAF/IDS blocks on web. What’s next?

A

Reduce rate, adjust user-agent/concurrency, and focus on manual low-noise enumeration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly