Here NAccount is username and assume we have the password of NAccount. Once we give enter it will ask password for NAccount user.
smbclient -U NAccount -L //10.6.0.2
-L --list=host get a list of shares available on a host.
Lets say we found a sharename called SYSVOL. so how can we access that?
smbclient -U NAccount //10.6.0.2/SYSVOL (again will ask for NAccount password)
Now we can see what is inside of SYSVOL folder.
smbclient -U SAccount //10.6.0.2/SpaceRace (once give enter will ask for SAccount password, assume we have cracked SAccount password as well)
Lets say we want to view lists of share folders using anonymous username. The smbmap can help. No password is required here. smbmap will also tell you which share folder are read only mode and which are not. smbclient will not tell you that. crackmapexec will also tell you like smbmap.
smbmap -u "Anonymous" -H 10.10.10.192
smbmap -H 10.10.10.192 -u '' -p ''
smbmap -H 10.10.10.192 -u ''
-H for Host or ip
Lets say we found profiles$ directory. Now lets connect with that directory using smbclient and no pass switch.
smbclient -N //10.10.10.192/profiles$
or
smbclient '//10.10.10.192/profiles$'
-N no pass, no kerberos authentication. we used quote because profile has $ sign. this could be issue. so used quote. you can try without quote.
smbclient to view list of shares without username and password:
smbclient -L 10.10.10.192 (hit enter for blank password)
or
smbclient -L 10.10.10.192 -U '' (-U '' means null user authentication)
or
smbclient -L 10.10.10.192 -U 'sdfsdfsd' (In all the cases, hit enter. It will ask for password. Again enter for blank password. smbclient will also work for random username that even don't exits. You may see some list of share folders.)
Once you get lots of folders or directories then you can mount that to /mnt for easier your work.
sudo mount -t cifs '//10.10.10.192/profiles$' /mnt
smbmap with username and password to see more shares:
smbmap -u 'support' -p '^#00BlackNight' -H 10.10.10.192
or
smbmap -u support -p '^#00BlackNight' -H 10.10.10.192
Avi
Comments
Post a Comment