Enumeració smb

SMB / samba #

  • Servei de compartició de carpetes
  • Autenticació usuaris/grups/dominis
  • Pensa que podem enumerar. Com podriem atacar?

scripts enumeracio SMB usant nmap #

Altres scripts smb #

 smbmap -H 172.20.0.152

    ________  ___      ___  _______   ___      ___       __         _______
   /"       )|"  \    /"  ||   _  "\ |"  \    /"  |     /""\       |   __ "\
  (:   \___/  \   \  //   |(. |_)  :) \   \  //   |    /    \      (. |__) :)
   \___  \    /\  \/.    ||:     \/   /\   \/.    |   /' /\  \     |:  ____/
    __/  \   |: \.        |(|  _  \  |: \.        |  //  __'  \    (|  /
   /" \   :) |.  \    /:  ||: |_)  :)|.  \    /:  | /   /  \   \  /|__/ \
  (_______/  |___|\__/|___|(_______/ |___|\__/|___|(___/    \___)(_______)
 -----------------------------------------------------------------------------
     SMBMap - Samba Share Enumerator | Shawn Evans - ShawnDEvans@gmail.com
                     https://github.com/ShawnDEvans/smbmap

[*] Detected 1 hosts serving SMB
[*] Established 0 SMB session(s)     
  • smbclient
capsinfo@capsinfo-Modern-15-F1MG:~$ smbclient -L //172.16.23.123 -U USER
Password for [WORKGROUP\XXX]:

	Sharename       Type      Comment
	---------       ----      -------
(...))

Moduls metsploit #

Per paassar un diccionari auxiliary/scanner/smb/smb_login