SMB
Server message block
default config
dangerous settings
browseable = yes
read only = no
writable = yes
guest ok = yes
enable privileges = yes
create mask = 0777
directory mask = 0777
logon script = script.sh
magic script = script.sh
magic output = script.out
restart service
connect
lists shares on server
connect to notes share
get status
smbstatus
nmap
rpclient
can offer us different requests
srvinfo - server info
enumdomains - enumerate all domains
querydominfo - provides domains, server and user info
netshareenumall - enumerates all shares
netsharegetinfo <share> - enumerates specific share
enumdomusers - enumerates all domain users
queryuser <rid> - enumerates specific user
Brute force user RIDs
alternative to this is to use samrdump.py from impacket.
smbmap
crackmapexec
enum4linux
Last updated