Windows Recon: SMBmap host discovery:
Using the smbmap tool to enumerate the target machine service
- allows users to enumerate samba share
- allows file upload/download/delete
- permission enumeration (writable share, meet Metasploit)
- etc.
smbmap -u guest -p '' -d . -H 10.10.10.50 #access SMB server as guest user;
smbmap -u Administrator -p 'valid_passwd' -d . -H 10.10.10.50 #access SMB server as Administrator (usually READ and WRITE permissions);
smbmap -H 10.10.10.50 -u Administrator -p 'valid_passwd' -x 'ipconfig' #execute command;
smbmap -H 10.10.10.50 -u Administrator -p 'valid_passwd' -L #list available drives;
smbmap -H 10.10.10.50 -u Administrator -p 'valid_passwd' -r 'C$' #list contents of C:\ drive;
smbmap -H 10.10.10.50 -u Administrator -p 'valid_passwd' --upload '/tmp/file_to_upload' 'C$\folder' #file upload;
smbmap -H 10.10.10.50 -u Administrator -p 'valid_passwd' --download 'C$\file_to_download' #file download;
Home of the smbtool