Server Message Block
Footprinting The Service
Nmap
sudo nmap 10.129.14.128 -sV -sC -p139,445
RPCclient


-U'%': Explicitly sends an empty username and no password. -N: Does not send any username or password, attempting to establish a null session.Query
Description
Search For Known SMB Version Vulnerabilities
Check For Shares Using Null Sessions
Brute Forcing

URL File attacks
Read / Upload access


smbmap with the -r or -R (recursive) option, one can browse the directories

Cpassword discovery
lsass.zip lsass.dmp
Alternate Data Streams (ADS)
Check Password Policy
User Discovery
Group discovery
Smbclient
Smbmap
Dangerous Settings
Setting
Description
Last updated