Share enumeration

The first step against an SMB server is listing its shares and, crucially, the read and write access the current identity has to each. A null, guest, or valid session all enumerate shares; the goal is to separate readable shares (loot) from writable ones (poisoning and planting).

bash
# List shares and per-share read/write access (null, guest, or creds)
nxc smb <target> -u '' -p '' --shares
nxc smb <target> -u user -p pass --shares
smbclient -L //<target>/ -N                 # list shares anonymously
# Spider a share for files
nxc smb <target> -u user -p pass -M spider_plus

Exploitation notes#

  • NetExec's --shares marks READ and WRITE per share, which immediately flags loot and poisoning targets.
  • Non-default shares (not C$, ADMIN$, IPC$, SYSVOL, NETLOGON) are usually the interesting business data.
  • A writable share leads to Writable share poisoning; a readable one to Loot and sensitive files.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more