The first step against an SMB server is listing its shares and, crucially, the read and write access the current identity has to each. A null, guest, or valid session all enumerate shares; the goal is to separate readable shares (loot) from writable ones (poisoning and planting).
# List shares and per-share read/write access (null, guest, or creds)
nxc smb <target> -u '' -p '' --shares
nxc smb <target> -u user -p pass --shares
smbclient -L //<target>/ -N # list shares anonymously
# Spider a share for files
nxc smb <target> -u user -p pass -M spider_plus
Exploitation notes#
- NetExec's
--sharesmarks READ and WRITE per share, which immediately flags loot and poisoning targets. - Non-default shares (not
C$,ADMIN$,IPC$,SYSVOL,NETLOGON) are usually the interesting business data. - A writable share leads to Writable share poisoning; a readable one to Loot and sensitive files.