> For the complete documentation index, see [llms.txt](https://kaelenvs-cybersecurity-notes.gitbook.io/kaelens-tryhackme-experience/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kaelenvs-cybersecurity-notes.gitbook.io/kaelens-tryhackme-experience/learning-paths/comptia-pentest+/penetration-testing-tools/nessus/scanning-a-web-application.md).

# Scanning a Web Application!

Following similar steps to the previous task, I began a New Scan named "TryHackMe (Web Application Test). This time running a Web Application Test instead of a Basic Network Scan. I configured the settings in the same way as the previous task. I made sure to scan all ports and ports with low bandwidth connection.&#x20;

Again, this scan took a long time so I waited for a while as Nessus completed its scan.&#x20;

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2FPbqvWEY3jtmqfzVSEP3Z%2F9.PNG?alt=media&amp;token=648446f5-aca1-4e13-b57c-f0b21a1cf60c" alt=""><figcaption><p>The HTTP server type and version.</p></figcaption></figure>

From the above screenshot, we can determine the plugin ID is 10107.&#x20;

The authentication page discovered by the scanner was login.php.

The file extension of the config backup was .bak.

The directory containing example documents was /external/phpids/0.6/docs/examples/.

The vulnerability this application is suscetible to that is associated with X-Frame-Options is clickjacking.&#x20;
