SMB (Server Message Block) is how Windows environments share files, and it is the richest file-share target. Attacks span reaching it without credentials (null session, guest), mapping and reading shares, abusing missing signing to relay authentication, poisoning writable shares to coerce or execute code on other users, looting readable shares for credentials, and the protocol-level remote code execution flaws in the SMB server itself.
Subtopics#
- Share enumeration: listing shares and their permissions.
- Null session: anonymous access to IPC and enumeration.
- Signing and relay: missing signing and NTLM relay.
- Writable share poisoning: planting files that act on other users.
- Loot and sensitive files: harvesting secrets from readable shares.
- Known SMB exploits: protocol-level remote code execution.